Description
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-06-09
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type confusion flaw in Microsoft Office applications that permits an attacker to execute code locally on the victim’s machine. By supplying data that is interpreted with an incompatible type, a malicious document can trigger arbitrary code execution. The flaw carries the CWE‑416 designation, indicating unsafe or unverifiable type handling. Successful exploitation would give the attacker full privileges on the affected computer, allowing data exfiltration, persistence, or lateral movement within the environment.

Affected Systems

The flaw affects several Microsoft Office and SharePoint products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, the macOS versions of Office 2019, 2021, 2024, Word 2016, and SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition. Only the product names are provided; no specific version details are listed. Organizations using any of these applications are potentially at risk.

Risk and Exploitability

With a CVSS score of 8.4 the vulnerability is considered high severity. EPSS score is not available, so the probability of exploitation cannot be quantified. The flaw is not recorded in the CISA KEV catalog, but the combination of a local code‑execution state and the prevalence of Office environments means the threat is still significant. The likely attack vector is local via opening a specially crafted document or email attachment, inferred from the description; no remote network exploitation is described. Once executed, code runs with the privileges of the user, potentially compromising the entire system.

Generated by OpenCVE AI on June 9, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update from the Microsoft Security Update Guide.
  • Ensure that automatic updates are enabled for all Office components so the patch is applied as soon as it is released.
  • If the patch cannot be installed immediately, restrict or quarantine Office documents from untrusted sources, enforce user confirmation before opening attachments, and consider implementing application whitelisting to block unapproved executables.

Generated by OpenCVE AI on June 9, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Outlook and Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:49:53.163Z

Reserved: 2026-05-12T16:06:43.097Z

Link: CVE-2026-45458

cve-icon Vulnrichment

Updated: 2026-06-09T19:53:33.395Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:20.060

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T20:15:07Z

Weaknesses