CVE-2026-64917: Microsoft Office Word Information Disclosure Vulnerability
Microsoft Office Word Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1000Patch KB5002901
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64917?
The severity of CVE-2026-64917 is medium with a score of 5.5.
Which software is affected by CVE-2026-64917?
CVE-2026-64917 affects Microsoft Word 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office 365 for Mac.
What type of vulnerability is CVE-2026-64917?
CVE-2026-64917 is an information disclosure vulnerability that allows unauthorized access to information.
How does CVE-2026-64917 impact users?
CVE-2026-64917 allows an unauthorized attacker to disclose information locally in Microsoft Office Word.
How do I fix CVE-2026-64917?
To fix CVE-2026-64917, ensure that you have the latest updates installed for the affected Microsoft Office software.