CVE-2026-45649: Office for Android Spoofing Vulnerability
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Other sources
Office for Android Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20131.20024
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45649?
The severity of CVE-2026-45649 is classified as high with a score of 7.1.
What types of software are affected by CVE-2026-45649?
CVE-2026-45649 affects Microsoft Office applications including Word, PowerPoint, and Excel for Android.
How can I fix CVE-2026-45649?
To fix CVE-2026-45649, ensure that you update your Microsoft Office for Android applications to the latest version provided by Microsoft.
What type of attack does CVE-2026-45649 facilitate?
CVE-2026-45649 facilitates spoofing attacks that allow unauthorized users to manipulate content locally in Office for Android.
Is user interaction required for CVE-2026-45649 to be exploited?
Yes, CVE-2026-45649 requires user interaction to be exploited, making it a concern for users of affected applications.