Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office has a vulnerability involving improper neutralization of special elements used in a command, which enables a command‑injection flaw. An attacker who can supply a specially crafted Office document or exploit a local Office instance may cause the application to execute arbitrary code on the affected system. The flaw could result in full compromise of the user’s machine, allowing an attacker to steal data, modify files, or covertly install additional malware. The weakness is classified as CWE‑77, representing an injection vulnerability.

Affected Systems

The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. No specific sub‑version data is listed, indicating that all released versions of these products are vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity flaw, and the EPSS score is not available, so the current exploitation probability is undefined. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or network‑based delivery of a malicious Office file that an unauthorized user can open. Once executed, the command‑injection flaw can allow code to run with the privileges of the Office process and potentially the current user.

Generated by OpenCVE AI on August 12, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Office security updates that address CVE‑2026‑65656.
  • Ensure automatic updates are enabled for Microsoft 365 and Office so future patches are applied promptly.
  • Configure Office to restrict or disable macro execution and enforce application isolation or Safe System Protection to mitigate the impact of any residual code‑execution risk.

Generated by OpenCVE AI on August 12, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-77
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:36.371Z

Reserved: 2026-07-22T18:16:01.896Z

Link: CVE-2026-65656

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:36.070Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:53.703

Modified: 2026-08-14T17:47:43.770

Link: CVE-2026-65656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:00:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')