CVE-2026-45466ImportantRevised 19 Jun
Microsoft Word Information Disclosure Vulnerability
Assessment
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- Severity
- Important
- CVSS base score
- 3.3CVSS:3.1/
AV:L/ AC:L/ PR:N/ UI:R/ S:U/ C:L/ I:N/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 0.5%Higher than 38.6% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office Word
- Weakness
- CWE-122: Heap-based Buffer Overflow
- Issued by
- Microsoft
- Published
- 9 Jun 2026 · June 2026
- Last revised
- 19 Jun 2026Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any actio…
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Microsoft Office9 affected products
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 365 for Mac
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
- Microsoft Office LTSC 2024 for 32-bit editions
- Microsoft Office LTSC 2024 for 64-bit editions
- Microsoft Office LTSC for Mac 2021
- Microsoft Office LTSC for Mac 2024