Information Disclosure Vulnerability in Microsoft Office Word
CVE-2026-55124

5.5MEDIUM

What is CVE-2026-55124?

An information disclosure vulnerability exists in Microsoft Office Word due to improper validation of specific input types. This flaw could allow an unauthorized attacker to gain access to sensitive information stored locally. Exploitation of this vulnerability can lead to unintended information exposure, increasing the risk for users who handle sensitive data. Users are advised to apply the available patches to mitigate the risks associated with this issue.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Office 2019 32-bit Systems 19.0.0

Microsoft Office 365 for Mac 1.0.0 < 16.111.26071215

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.