ZeroHour

CVE-2026-40367

CVSS 3.1
8.4 high
EPSS
<1%p38
Published
()
Modified
Description

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, office, office long term servicing channel, sharepoint server, word
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news