CVE-2026-35440

EUVD-2026-29638
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
microsoft365_apps
-
microsoft365_apps
-
microsoft365_apps
𝑥
< 2604
microsoftoffice
𝑥
< 2604
𝑥
= Vulnerable software versions