Home
HIGH: 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
19.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
-
affected
16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
-
affected
-
affected
16.0.0 (custom) before 16.0.5556.1005
affected
16.0.0 (custom) before 16.0.10417.20153
affected
16.0.0 (custom) before 16.0.19725.20384
affected
16.0.1 (custom) before 16.0.5556.1000
affected
Description
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Problem types
CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456 (Microsoft Outlook and Word Remote Code Execution Vulnerability)