CVE-2026-83951: Microsoft Office Word Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Office Word Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002923 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896
Event History
Frequently Asked Questions
What access and user interaction are required for exploitation?
Exploitation is local and requires user interaction. The attacker does not need privileges, but the provided data does not specify the exact interaction or delivery mechanism.
What is the potential impact if exploited?
The vulnerability can disclose information due to a buffer over-read in Microsoft Word. The supplied severity vector indicates high confidentiality impact, with no integrity or availability impact.
Which Microsoft Office products are listed as affected?
The affected software list includes Microsoft 365 Apps for Enterprise, Word 2016, Office 2019 for 32-bit and 64-bit editions, and Office LTSC 2021 and 2024 for 32-bit and 64-bit editions.