Information Disclosure Vulnerability in Microsoft Office
CVE-2026-45485

3.3LOW

What is CVE-2026-45485?

An out-of-bounds read vulnerability in Microsoft Office enables unauthorized individuals to access sensitive information locally. By exploiting this flaw, attackers can potentially retrieve confidential data, posing a significant risk to user security and privacy. It is crucial for users of affected Microsoft Office versions to apply the latest updates to mitigate this security risk.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Office 2016 32-bit Systems 16.0.0 < 16.0.5556.1005

Microsoft Office 2019 32-bit Systems 19.0.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.