Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: 2026-06-09
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office components have an out-of-bounds read that permits local attackers to read memory or files beyond intended bounds, enabling disclosure of sensitive information. The weakness is identified as CWE-125. Because the read occurs during normal operation of Office, an adversary with local execution privileges can potentially retrieve confidential data stored in documents or the system. The vulnerability does not provide direct control over the system or network but threatens confidentiality by exposing private content.

Affected Systems

Affected vendors and products include Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, SharePoint Enterprise Server 2016, Sharepoint Server 2019, and SharePoint Server Subscription Edition. Specific version ranges are not enumerated in the advisory, so all released editions of these products should be considered potentially affected until a patch is applied. Microsoft's update guidance provides the precise revision numbers.

Risk and Exploitability

With a CVSS score of 3.3 the severity is low, and the EPSS score is not reported, indicating that there is no recent evidence of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Attacks would require an attacker to have local access to the affected machine, typically through a user account with elevated privileges. While the impact is limited to confidentiality and only affects local systems, organizations should still patch promptly to eliminate the possibility of local disclosure.

Generated by OpenCVE AI on June 9, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update for Microsoft Office and SharePoint from the Microsoft Security Update Guide.
  • Restrict file system permissions so that only authorized users can open or modify Office documents and related temporary files.
  • Enable auditing on critical documents and audit logs to detect any unauthorized access attempts, and apply least privilege practices for local accounts.

Generated by OpenCVE AI on June 9, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:49:42.197Z

Reserved: 2026-05-12T16:07:22.617Z

Link: CVE-2026-45485

cve-icon Vulnrichment

Updated: 2026-06-09T20:05:51.152Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:23.010

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T00:00:10Z

Weaknesses