CVE-2026-55047: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1000Patch KB5002887 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20434Patch KB5002882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002885 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002892
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55047?
The severity of CVE-2026-55047 is rated as medium with a score of 5.5.
How does CVE-2026-55047 impact Microsoft Office?
CVE-2026-55047 allows an unauthorized attacker to disclose sensitive information through an out-of-bounds read in Microsoft Office.
What products are affected by CVE-2026-55047?
CVE-2026-55047 affects Microsoft SharePoint Server, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office 365 for Mac.
How can I mitigate CVE-2026-55047?
Mitigation for CVE-2026-55047 requires applying security updates and patches provided by Microsoft.
What type of vulnerability is CVE-2026-55047?
CVE-2026-55047 is classified as an information disclosure vulnerability.