CVE-2026-26113
8.4Microsoft · Office
An untrusted pointer dereference vulnerability in Microsoft Office permits local, unauthorized attackers to execute arbitrary code on the target system.
Executive summary
A critical untrusted pointer dereference vulnerability in Microsoft Office enables unauthorized local code execution, posing a significant risk to system integrity and data security.
Vulnerability
This flaw involves an untrusted pointer dereference (CWE-822) within the Microsoft Office suite. The vulnerability can be triggered by an unauthorized attacker with local access, allowing them to gain control over the execution flow of the application.
Business impact
The ability for an unauthorized local attacker to execute code grants them the potential to compromise sensitive data, install persistent malware, or escalate privileges within the local environment. With a CVSS score of 8.4, this vulnerability represents a high-severity threat that could lead to full system compromise, resulting in significant operational downtime and potential data exfiltration.
Remediation
Immediate Action: Organizations must apply the security updates provided by Microsoft via the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26113 to remediate the vulnerable code.
Proactive Monitoring: Security teams should monitor system access logs for unusual process execution patterns or unexpected spikes in Office application resource consumption that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection solutions are configured to detect and block suspicious child processes initiated by Office applications, and enforce the principle of least privilege for local users to limit the potential impact of code execution.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a substantial risk to internal systems, and immediate patching is required to prevent unauthorized code execution. Administrators should prioritize the deployment of the vendor-supplied updates across all affected Office versions to ensure the underlying pointer dereference flaw is corrected.
More Microsoft CVEs
Sources
- Microsoft Office Remote Code Execution Vulnerability Vendor advisory