CVE-2026-40421

EUVD-2026-29678
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
microsoft365_apps
-
microsoft365_apps
-
microsoft365_apps
𝑥
< 2604
microsoftoffice
𝑥
< 2604
𝑥
= Vulnerable software versions