CVE-2026-62804

EUVD-2026-73923
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
microsoft365_apps
-
microsoft365_apps
-
microsoftmicrosoft_365
-
microsoftoffice_2016
-
microsoftoffice_2016
-
microsoftoffice_2019
-
microsoftoffice_2019
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2021
-
microsoftoffice_2024
-
microsoftoffice_2024
-
𝑥
= Vulnerable software versions