Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves improper neutralization of special elements used in a command, allowing a command injection flaw in Microsoft Office. An authorized local user who can produce or modify Office documents may exploit this weakness to execute arbitrary commands under the application's user context, thereby elevating privileges on the host system. The flaw is described by CWE‑77 and can lead to a compromise of confidentiality, integrity, or availability if the attacker gains elevated rights.

Affected Systems

Affected installations include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. No specific version ranges are listed, so all instances of these products are considered vulnerable until updated.

Risk and Exploitability

With a CVSS score of 7.8, the threat is classified as high severity. The EPSS score is not available, so the current probability of exploitation is unknown, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker who already has read/write access to Office files can craft a malicious package that triggers the command injection, chaining it to privilege escalation on the target machine.

Generated by OpenCVE AI on August 12, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update that addresses CVE‑2026‑68792.
  • Upgrade all affected Office installations to the most recent supported release that contains the fix.
  • If an update cannot be applied immediately, enforce strict document control: only allow trusted documents to be opened and restrict automation features such as OfficeAutoOpen from untrusted sources.
  • Monitor system processes for unexpected command execution or usage of command-line utilities originating from Office components.
  • Configure application whitelisting to block unauthorized execution of Office binaries or injected commands.

Generated by OpenCVE AI on August 12, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
Title Microsoft Office Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-77
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:49.050Z

Reserved: 2026-07-31T16:33:08.216Z

Link: CVE-2026-68792

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:30.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:02.627

Modified: 2026-08-14T17:20:22.570

Link: CVE-2026-68792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:00:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')