8.4
CVE-2026-40367
- EPSS 0.45%
- Veröffentlicht 12.05.2026 16:59:20
- Zuletzt bearbeitet 01.06.2026 19:16:34
- Erkennungen
Microsoft Word Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x86
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform macos
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x86
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform macos
Microsoft ≫ Sharepoint Server SwEdition subscription Version < 16.0.19725.20280
Microsoft ≫ Sharepoint Server Version 2016 SwEdition enterprise
Microsoft ≫ Sharepoint Server Version 2019
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.372 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367