CVE-2026-45485: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Patch KB5002878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45485?
The severity of CVE-2026-45485 is rated as low with a score of 3.3.
What types of software are affected by CVE-2026-45485?
CVE-2026-45485 affects Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft 365 Apps, Microsoft 365 Apps for Enterprise, and Microsoft SharePoint Server.
How do I fix CVE-2026-45485?
To fix CVE-2026-45485, ensure that your Microsoft Office software is updated to the latest version provided by Microsoft.
What is the risk associated with CVE-2026-45485?
CVE-2026-45485 has a risk rating of 17, indicating it is low risk but still poses a potential threat of information disclosure.
Can CVE-2026-45485 be exploited remotely?
CVE-2026-45485 cannot be exploited remotely, as it requires local access to the affected system.