CVE-2026-44818

EUVD-2026-35661
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
microsoft365_apps
-
microsoft365_apps
-
microsoftmicrosoft_365
-
microsoftoffice_2019
-
microsoftoffice_2019
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2024
-
microsoftoffice_2024
-
microsoftoffice_2024
-
microsoftoffice_online_server
-
microsoft365_apps
𝑥
< 2605
microsoftoffice
𝑥
< 2605
𝑥
= Vulnerable software versions