CVE-2026-55124

EUVD-2026-44188
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45.8%
Affected Products (NVD)
VendorProductVersion
microsoft365_apps
-
microsoft365_apps
-
microsoftmicrosoft_365
-
microsoftoffice_2019
-
microsoftoffice_2019
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2024
-
microsoftoffice_2024
-
microsoftoffice_2024
-
microsoftoffice_online_server
𝑥
< 16.0.10417.20175
microsoftsharepoint_server
𝑥
< 16.0.19725.20434
microsoft365_apps
𝑥
< 2606
microsoftoffice
𝑥
< 2606
𝑥
= Vulnerable software versions