CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability
Microsoft Outlook and Word Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1000Patch KB5002879 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45458?
CVE-2026-45458 has a severity rating of 8.4, indicating a high risk level.
How does CVE-2026-45458 impact Microsoft Office users?
CVE-2026-45458 allows an unauthorized attacker to execute code locally on vulnerable versions of Microsoft Office.
What software is affected by CVE-2026-45458?
CVE-2026-45458 affects Microsoft SharePoint Server, Microsoft Word 2016, Microsoft 365 Apps, and newer versions of Microsoft Office.
How can CVE-2026-45458 be mitigated?
To mitigate CVE-2026-45458, users should update their Microsoft Office applications to the latest version provided by Microsoft.
What type of vulnerability is CVE-2026-45458 classified as?
CVE-2026-45458 is classified as a type confusion vulnerability leading to remote code execution in Microsoft Office applications.