CVE-2026-80089: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002916 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204
Event History
Frequently Asked Questions
Which Office deployments are in scope?
The affected software list includes Microsoft Office 2016; Microsoft 365 Apps for Enterprise; Office 365 for Mac; Office LTSC for Mac 2021 and 2024; and Office LTSC 2021 and 2024 for Windows, including both 32-bit and 64-bit editions where listed.
What does an attacker need to exploit this issue?
The issue is described as exploitable over a network with low attack complexity and no privileges required. User interaction is required, so exploitation depends on a user taking an attacker-influenced action.
What is the expected impact if exploitation succeeds?
Successful exploitation can disclose information through an out-of-bounds read. The provided vector indicates high confidentiality impact, with no stated integrity or availability impact.