CVE-2026-80078: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker can be unauthorized and attack over a network, but exploitation requires user interaction. The vulnerability is an out-of-bounds read that may disclose information; the provided data does not indicate that it enables modification or denial of service.
Which Office deployments are identified as affected?
The listed affected products are Microsoft 365 Apps for Enterprise; Office 2019 32-bit editions; Office LTSC 2021 and 2024 in 32-bit and 64-bit editions; Office 365 for Mac; and Office LTSC for Mac 2024.