7.7

CVE-2026-42832

Medienbericht

Microsoft Office Spoofing Vulnerability

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftExcel SwPlatformandroid Version < 16.0.19822.20190
MicrosoftOffice Version2021 SwEditionltsc SwPlatformmacos
MicrosoftOffice Version2024 SwEditionltsc SwPlatformmacos
MicrosoftWord SwPlatformandroid Version < 16.0.19822.20190
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.126
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
secure@microsoft.com 7.7 2.5 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.