CVE-2026-45458
Microsoft · Office
A type confusion vulnerability in Microsoft Office allows an unauthorized attacker to execute arbitrary code locally on an affected system.
Executive summary
A type confusion vulnerability in Microsoft Office enables unauthorized local code execution, posing a significant threat to workstation security.
Vulnerability
This is a type confusion vulnerability caused by the improper handling of resources in Microsoft Office. Unauthorized attackers can exploit this to achieve local code execution, typically requiring the victim to interact with a malicious file.
Business impact
With a CVSS score of 8.4, this high-severity flaw can lead to significant business disruption. Successful exploitation allows for unauthorized code execution, which could be leveraged to gain persistence on a machine, access sensitive internal documents, or steal credentials stored on the endpoint.
Remediation
Immediate Action: Apply the most recent security patches for Microsoft Office provided by Microsoft.
Proactive Monitoring: Utilize Endpoint Detection and Response (EDR) tools to alert on unauthorized or suspicious behavior initiated by Office applications.
Compensating Controls: Enforce strict file-type blocking policies on email gateways to prevent users from opening potentially malicious, non-standard document formats.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The severity of this vulnerability necessitates immediate patching across the enterprise. Administrators must ensure that all Office software is updated and that appropriate security policies, such as macro restrictions, are in place to mitigate the risk of local execution.