7.8

CVE-2026-55949

Microsoft Excel Remote Code Execution Vulnerability

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx64
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx86
MicrosoftExcel Version2016 HwPlatformx64
MicrosoftExcel Version2016 HwPlatformx86
MicrosoftMicrosoft 365 Version- SwPlatformmacos
MicrosoftOffice 2019 Version- HwPlatformx64
MicrosoftOffice 2019 Version- HwPlatformx86
MicrosoftOffice 2021 Version- SwEditionltsc SwPlatform- HwPlatformx64
MicrosoftOffice 2021 Version- SwEditionltsc SwPlatform- HwPlatformx86
MicrosoftOffice 2021 Version- SwEditionltsc SwPlatformmacos HwPlatform-
MicrosoftOffice 2024 Version- SwEditionltsc SwPlatform- HwPlatformx64
MicrosoftOffice 2024 Version- SwEditionltsc SwPlatform- HwPlatformx86
MicrosoftOffice 2024 Version- SwEditionltsc SwPlatformmacos HwPlatform-
MicrosoftOffice Online Server Version < 16.0.10417.20175
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.222
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55949
Vendor Advisory