CVE-2026-70317: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70317?
CVE-2026-70317 has a medium severity rating of 5.5.
How does CVE-2026-70317 affect Microsoft Office?
CVE-2026-70317 allows an unauthorized attacker to disclose sensitive information through the use of uninitialized resources in Microsoft Office.
Which versions of Microsoft Office are vulnerable to CVE-2026-70317?
The vulnerable versions include Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft Office 365 for Mac, and Microsoft Office LTSC 2024 for 64-bit editions.
What is the impact of CVE-2026-70317?
The impact of CVE-2026-70317 is primarily local information disclosure, which could allow unauthorized users to access confidential data.
How can I mitigate CVE-2026-70317?
To mitigate CVE-2026-70317, it's recommended to apply any available security updates provided by Microsoft for the affected Office versions.