CVE-2026-40418: Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Other sources
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40418?
CVE-2026-40418 has a high severity rating of 7.8.
How do I fix CVE-2026-40418?
To mitigate CVE-2026-40418, ensure that you apply the latest security updates provided by Microsoft for your Office version.
What types of software are affected by CVE-2026-40418?
CVE-2026-40418 affects Microsoft Office Long Term Servicing Channel, Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office 2019 (32-bit and 64-bit editions), and Microsoft Office LTSC 2021 and 2024.
Who can exploit CVE-2026-40418?
CVE-2026-40418 can be exploited by an authorized attacker who has local access to the affected Microsoft Office products.
What vulnerability type is CVE-2026-40418 classified as?
CVE-2026-40418 is classified as a 'Use After Free' vulnerability.