CVE-2026-55035
Analyzed Analyzed - Analysis Complete

Microsoft Office Out-of-Bounds Read Vulnerability

Vulnerability report for CVE-2026-55035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft office_2019 *
microsoft office_2019 *
microsoft office_2016 *
microsoft office_2016 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55035 is an out-of-bounds read vulnerability in Microsoft Office. This means that the software reads data beyond the intended boundary, which can allow an unauthorized attacker to access sensitive information stored in memory.

The vulnerability is classified as an information disclosure issue, meaning the primary risk is the exposure of confidential data rather than direct system compromise or code execution.

According to the CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), the attack requires local access, low attack complexity, no privileges, and user interaction (such as opening a malicious file). The impact is high for confidentiality but does not affect integrity or availability.

Detection Guidance

Detection of this vulnerability requires checking for specific Microsoft Office versions and applying the latest security updates. Use the Microsoft Update Catalog or Windows Update to verify patch status. No direct commands are provided in the available resources.

Impact Analysis

If you use Microsoft Office, this vulnerability could allow an attacker to access sensitive information stored on your system.

  • An attacker could craft a malicious file (e.g., a Word or Excel document) and trick you into opening it.
  • Once opened, the file could exploit the out-of-bounds read flaw to disclose information from your system's memory, such as passwords, documents, or other confidential data.

The impact is limited to information disclosure, meaning the attacker could steal data but not necessarily take control of your system or delete files.

Compliance Impact

This vulnerability could have compliance implications depending on the type of data you handle and the regulations your organization follows.

  • GDPR: If the disclosed information includes personal data of EU citizens, this could be considered a data breach. Organizations may need to report the incident to authorities and affected individuals, depending on the risk level.
  • HIPAA: If the vulnerability leads to the exposure of protected health information (PHI), it could constitute a breach under HIPAA. Covered entities would need to follow breach notification rules, including notifying affected individuals and the Department of Health and Human Services.
  • Other standards (e.g., PCI DSS, SOX): If the disclosed data includes payment card information or financial records, this could violate compliance requirements for data protection and breach reporting.

Failure to mitigate such vulnerabilities could result in regulatory penalties, legal liabilities, or reputational damage.

Mitigation Strategies

The provided context does not include specific mitigation steps for CVE-2026-55035. However, general best practices for addressing Microsoft Office vulnerabilities include:

  • Apply the latest security updates from Microsoft as soon as they are available. Check the Microsoft Update Guide for patches related to CVE-2026-55035.
  • Restrict access to Microsoft Office applications to trusted users only, especially in environments where sensitive information is handled.
  • Monitor Microsoft's security advisories for additional guidance or workarounds related to this vulnerability.

For the most accurate and up-to-date mitigation steps, refer to the official Microsoft resource.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart