← back
CVE-2026-21509

Microsoft Office Security Feature Bypass Vulnerability

CVSS 7.8 HIGHEPSS 72.2%● KEVCWE-807
In short

Microsoft Office accepts untrusted data when making security decisions, allowing someone on your computer to bypass built-in security protections. This could let malicious content run when it should be blocked.

Technical detail

CWE-807 vulnerability in Microsoft Office's security decision logic trusts user-controllable input to determine security policy enforcement. Local attacker can manipulate inputs to circumvent access controls or content restrictions; requires local access but bypasses intended security boundaries.

Summary generated and translated by AI from the official description.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →