ZeroHour

CVE-2026-45456

CVSS 3.1
8.4 high
EPSS
<1%p37
Published
()
Modified
Description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024, sharepoint server
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news