CVE-2026-69739: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20976 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002916 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20207
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
The affected software list includes Microsoft Office 2016, Microsoft Office 2019 (32-bit and 64-bit), Microsoft 365 Apps for Enterprise, and Microsoft Office LTSC 2021 and LTSC 2024 (32-bit and 64-bit).
What access does an attacker need to exploit this issue?
The vector is network-based and no privileges are required. User interaction is required, so exploitation depends on a user taking an action.
What is the expected security impact?
The vulnerability can expose information, with high confidentiality impact. It has no listed integrity or availability impact, and the scope is unchanged.