Improper Access Control in Microsoft Office
CVE-2026-42832

7.7HIGH

What is CVE-2026-42832?

An improper access control vulnerability in Microsoft Office allows unauthorized attackers to execute spoofing attacks locally. This type of vulnerability can compromise the integrity of documents and potentially lead to unauthorized information disclosure, manipulating users into believing they are interacting with legitimate content. It's essential for users and organizations to stay informed about this vulnerability and apply necessary patches to safeguard their systems.

Affected Version(s)

Microsoft Excel for Android 16.0.0.0 < 16.0.19822.20190

Microsoft Office LTSC for Mac 2021 16.0.1 < 16.109.26051019

Microsoft Office LTSC for Mac 2024 16.0.0 < 16.109.26051019

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.