Description
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a type‑confusion flaw (CWE‑843) in Microsoft Office that allows an unauthorized attacker to execute code locally on an affected system. By supplying specially crafted input that the Office components treat as an incompatible type, the attacker can gain code‑execution authority with the privileges of the current user. This can lead to data disclosure, credential theft, or further compromise of the machine.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and their Mac counterparts (LTSC 2021 and LTSC 2024 for Mac). The vulnerability applies across the listed Windows and macOS client versions, as indicated by the CPE entries. No specific version numbers are provided in the CNA data, so all releases within the scopes are considered vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies this flaw as high severity. EPSS is not available, so the current exploitation probability is unknown but not documented as already exploited; the vulnerability is also not listed in the CISA KEV catalog. The likely attack vector is a malicious Office document or content that the user opens or a plugin that feeds incompatible data to Office. An attacker must be able to supply that input on the victim’s machine; remote delivery may be possible if the victim downloads a crafted file. Because the impact is local code execution, a compromised user account or shared network drive can be used to deliver the payload. The overall risk is therefore moderate to high, especially in environments where users frequently open untrusted documents.

Generated by OpenCVE AI on August 12, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft patch for CVE-2026-64904 from the Microsoft Security Update Guide immediately.
  • Enable and enforce automatic updates for all affected Office products to ensure the fix is applied without manual intervention.
  • Restrict user ability to open or execute untrusted Office documents by enforcing document validation policies or using application whitelisting; additionally, consider disabling legacy file formats and blocking macros unless required.

Generated by OpenCVE AI on August 12, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:23.659Z

Reserved: 2026-07-20T20:25:40.975Z

Link: CVE-2026-64904

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:04.952Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:51.323

Modified: 2026-08-14T15:10:10.120

Link: CVE-2026-64904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:00:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')