CVE-2026-21514
Microsoft Word Security Feature Bypass Vulnerability
In short
Microsoft Word relies on untrusted data to make security decisions, allowing attackers to bypass security protections on a local computer. This means malicious files or inputs can trick Word into ignoring its safety measures.
Technical detail
CWE-807 vulnerability in Word's security decision logic accepts untrusted input without proper validation, enabling local attackers to circumvent security features. Requires local access and interaction with a malicious file; impact includes bypassing protected view and macro execution controls.
Summary generated and translated by AI from the official description.
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Affected products
Microsoft · Microsoft 365 Apps for EnterpriseMicrosoft · Microsoft Office LTSC 2021Microsoft · Microsoft Office LTSC 2024Microsoft · Microsoft Office LTSC for Mac 2021Microsoft · Microsoft Office LTSC for Mac 2024Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →