ZeroHour

CVE-2026-40421

CVSS 3.1
4.3 medium
EPSS
<1%p48
Published
()
Modified
Description

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Vendors
microsoft
Products
365 apps, office, office long term servicing channel, word
Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.