CVE-2026-20943: Microsoft Office Click-To-Run Remote Code Execution Vulnerability
Microsoft Office Click-To-Run Remote Code Execution Vulnerability
Other sources
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19426.20170 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19127.20442Patch KB5002822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5535.1001Patch KB5002828 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20083Patch KB5002825 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5535.1000Patch KB5002826
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20943?
CVE-2026-20943 is rated as a medium elevation of privilege vulnerability.
How do I fix CVE-2026-20943?
To fix CVE-2026-20943, apply the relevant security updates provided by Microsoft for the affected products.
Which products are affected by CVE-2026-20943?
CVE-2026-20943 affects Microsoft SharePoint Server 2019, Office 2016, SharePoint Enterprise Server 2016, Office Deployment Tool, and SharePoint Server Subscription Edition.
Can CVE-2026-20943 allow remote code execution?
No, CVE-2026-20943 allows unauthorized local code execution due to an untrusted search path in Microsoft Office.
Is CVE-2026-20943 exploitable without user interaction?
CVE-2026-20943 may require user interaction for exploitation, as it involves executing code locally.