CVE-2026-45466: Microsoft Word Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Word Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45466?
The severity of CVE-2026-45466 is classified as low with a score of 3.3.
How does CVE-2026-45466 affect Microsoft Word users?
CVE-2026-45466 allows an unauthorized attacker to disclose information locally due to a heap-based buffer overflow.
Which Microsoft products are impacted by CVE-2026-45466?
CVE-2026-45466 affects Microsoft 365 Apps for Enterprise, various editions of Microsoft Office LTSC for both Windows and Mac.
How can I mitigate the risks associated with CVE-2026-45466?
To mitigate the risks related to CVE-2026-45466, ensure that your Microsoft Office applications are updated to the latest versions.
Is there a workaround for CVE-2026-45466 while waiting for a patch?
Currently, no specific workarounds have been documented for CVE-2026-45466, so applying updates is the recommended action.