← back
CVE-2026-21514

Microsoft Word Security Feature Bypass Vulnerability

CVSS 7.8 HIGHEPSS 1.5%● KEVCWE-807
In short

Microsoft Word relies on untrusted data to make security decisions, allowing attackers to bypass security protections on a local computer. This means malicious files or inputs can trick Word into ignoring its safety measures.

Technical detail

CWE-807 vulnerability in Word's security decision logic accepts untrusted input without proper validation, enabling local attackers to circumvent security features. Requires local access and interaction with a malicious file; impact includes bypassing protected view and macro execution controls.

Summary generated and translated by AI from the official description.
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →