Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read flaw in various Microsoft Office versions enables an attacker with local access to read memory that should not be accessible. The vulnerability directly exposes sensitive information stored in the Office application process and is classified as CWE-125. As a result, confidential documents, credentials, or other data that remain in memory at the time of exploitation could be obtained by a local user, leading to confidentiality breaches.

Affected Systems

Microsoft Office products across the desktop ecosystem, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Office 365 for Mac, Office LTSC for Mac 2021 and Office LTSC for Mac 2024, are affected. The severity applies to both Windows and macOS builds. Specific patch versions are not listed in the vendor statement, so all current releases require updating as soon as an official fix is released.

Risk and Exploitability

The CVSS score of 7.1 marks this vulnerability as high‑severity, though the EPSS score indicates a very low probability of exploitation today and it is not present in CISA’s KEV catalog. The weakness is exploitable only from a local context, meaning the attacker must have some execution lever such as a malicious Office document opened by the user. By reading beyond a buffer boundary, the attacker can glean contents from the Office process memory, but no direct privilege escalation or remote code execution is described.

Generated by OpenCVE AI on July 31, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all installed Microsoft Office applications to the latest cumulative patches available through the Microsoft Security Response Center.
  • Validate that Office document execution is restricted to trusted sources only, preventing automated opening of potentially malicious files.
  • Enforce least privilege for all users interacting with Office products, ensuring accounts lack administrative rights that could amplify the impact of a memory disclosure.

Generated by OpenCVE AI on July 31, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:51.484Z

Reserved: 2026-06-19T13:54:04.006Z

Link: CVE-2026-56193

cve-icon Vulnrichment

Updated: 2026-07-14T17:37:14.331Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses