ZeroHour

CVE-2026-20948

CVSS 3.1
7.8 high
EPSS
<1%p45
Published
()
Modified
Description

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, office, office long term servicing channel, sharepoint server, word
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.