Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: 2026-06-09
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read that allows an attacker to read memory containing sensitive data, resulting in local information disclosure. This flaw is identified as CWE‑125. The impact is limited to confidentiality loss for data that may be stored in Office documents or user session memory; there is no known effect on integrity or availability.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, 2019, 2021, 2024, Office 365 for Mac, Office LTSC 2021 and 2024, and the corresponding Mac versions. SharePoint Server products such as SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are also listed as affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited current exploit landscape. Because the exploit requires local access to an Office installation, the likely vector is a local user or malicious code executing on the infected host. The attacker can read data from memory buffers that are improperly bounded, leading to the disclosure of sensitive information.

Generated by OpenCVE AI on June 9, 2026 at 19:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Office update released by Microsoft for the affected versions
  • Enable automatic updates in Microsoft Office or Windows Update to ensure the patch is installed promptly
  • If patching is delayed, restrict local user privileges to prevent execution of Office applications from untrusted locations

Generated by OpenCVE AI on June 9, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:49:50.017Z

Reserved: 2026-05-07T20:07:18.272Z

Link: CVE-2026-44821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:18.443

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-44821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T03:45:21Z

Weaknesses