Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read flaw in Microsoft Office allows an unauthorized local attacker to extract data stored in memory, leading to the disclosure of confidential information. The weakness corresponds to CWE-125, which describes improper handling of array bounds that can leak sensitive data. It requires an attacker with local access to the target system.

Affected Systems

The vulnerability impacts a broad set of Microsoft products. Affected vendors and products include Microsoft 365 Apps for Enterprise; Microsoft Office 2016, 2019, Office 2021 LTSC, Office 2024 LTSC; Microsoft Office 365 for Mac; Office LTSC for Mac 2021 and 2024; and Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Version information is limited to the product families listed above.

Risk and Exploitability

The CVSS v3.1 score of 5.5 demonstrates a moderate risk level. Because this flaw is local to the target system, it requires that the attacker already have unauthorized local access—either physical or through compromised user credentials—to exploit it. The EPSS score of < 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. If the flaw is leveraged, sensitive memory contents could be read by the attacker locally, potentially exposing passwords, cryptographic keys, or other private data stored by Office applications.

Generated by OpenCVE AI on July 31, 2026 at 06:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft's latest security updates for the affected Office and SharePoint products; updates are published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55047
  • Disable or remove any unused Office components or legacy features that may still load the vulnerable code, and configure the Office deployment to use secure defaults (e.g., disable macros, restrict add‑ins)
  • Enforce strict local privilege controls: limit local user accounts to the minimum necessary privileges and restrict physical or credential access to the devices to prevent unauthorized local attackers

Generated by OpenCVE AI on July 31, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:57:02.602Z

Reserved: 2026-06-16T14:13:49.836Z

Link: CVE-2026-55047

cve-icon Vulnrichment

Updated: 2026-07-14T18:54:25.678Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:00:08Z

Weaknesses