CVE-2026-83949: Microsoft Office Word Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Office Word Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002923 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960
Event History
Frequently Asked Questions
What access and user interaction are required for exploitation?
The attacker needs local access, but no privileges are required. Exploitation also requires user interaction.
What is the likely impact if exploitation succeeds?
Successful exploitation can disclose information. The provided severity vector indicates high confidentiality impact, with no integrity or availability impact.
Which Office deployments are identified as affected?
The affected software list includes Microsoft 365 Apps for Enterprise, Word 2016, Office 2019 in 32-bit and 64-bit editions, and Office LTSC 2021 and 2024 in both 32-bit and 64-bit editions.