CVE-2026-45456: Microsoft Outlook and Word Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Outlook and Word Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1000Patch KB5002879 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45456?
CVE-2026-45456 has a high severity rating of 8.4.
How do I fix CVE-2026-45456?
To fix CVE-2026-45456, ensure that you apply the latest security patches provided by Microsoft for affected products.
What products are affected by CVE-2026-45456?
CVE-2026-45456 affects Microsoft SharePoint Server, Microsoft Word 2016, Microsoft 365 Apps for Enterprise, and other versions of Microsoft Office.
What type of vulnerability is CVE-2026-45456?
CVE-2026-45456 is classified as a remote code execution vulnerability due to type confusion.
What are the potential impacts of CVE-2026-45456?
Exploiting CVE-2026-45456 can allow an unauthorized attacker to execute code locally, potentially compromising system integrity.