CVE-2026-55124
Analyzed Analyzed - Analysis Complete

Microsoft Office Word Information Disclosure Vulnerability

Vulnerability report for CVE-2026-55124, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft word 2016
microsoft word 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)
microsoft office_online_server to 16.0.10417.20175 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1287 The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55124 is a vulnerability in Microsoft Office Word. It involves improper validation of a specific type of input, which allows an unauthorized attacker to disclose information locally. This means the attacker does not need remote access but must have some level of local access to exploit the flaw.

The vulnerability is classified as an information disclosure issue, meaning the primary risk is the exposure of sensitive data rather than direct system compromise or code execution.

  • Affected software: Microsoft Office Word.
  • Attack vector: Local (AV:L), meaning the attacker must have access to the system where the vulnerable software is installed.
  • Privileges required: None (PR:N), meaning the attacker does not need elevated privileges to exploit the vulnerability.
  • User interaction: Required (UI:R), meaning the victim must perform some action, such as opening a malicious file, for the exploit to succeed.
Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-55124 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office Word or monitoring for unusual local information disclosure behavior, but no technical details or commands are specified in the given resources.

To detect this vulnerability, you may need to refer to Microsoft's official guidance or security tools that scan for vulnerable software versions. The CVE description indicates it involves improper input validation in Microsoft Office Word, so ensuring all Office installations are updated to the latest patched version is critical.

Impact Analysis

If you use Microsoft Office Word, this vulnerability could impact you in the following ways:

  • Unauthorized disclosure of sensitive information: An attacker could exploit this flaw to access and extract confidential or personal data stored locally on your system.
  • Potential for further attacks: The disclosed information could be used to facilitate additional attacks, such as phishing or targeted exploitation of other vulnerabilities.
  • Risk of data breaches: If the disclosed information includes regulated or protected data (e.g., financial, medical, or personal records), it could lead to compliance violations or legal consequences.

The impact is limited to information disclosure, so the attacker cannot directly modify or delete data or execute malicious code on your system through this vulnerability alone.

Compliance Impact

This vulnerability could affect compliance with common standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a data breach. GDPR requires organizations to implement appropriate security measures to protect personal data. Failure to patch or mitigate this vulnerability could result in non-compliance, leading to fines or legal action.
  • HIPAA (Health Insurance Portability and Accountability Act): If the disclosed information includes protected health information (PHI), this vulnerability could result in a breach of HIPAA's Security Rule. Covered entities and business associates must ensure the confidentiality, integrity, and availability of PHI. Exploitation of this vulnerability could lead to violations and penalties.
  • Other regulations: Depending on the industry and type of data involved, this vulnerability could also impact compliance with other standards such as PCI DSS (for payment card data) or sector-specific regulations.

Organizations should assess the types of data processed or stored by Microsoft Office Word and determine if exploitation of this vulnerability could lead to non-compliance with applicable regulations. Prompt patching and mitigation are recommended to avoid potential compliance risks.

Mitigation Strategies
  • Apply the latest security updates provided by Microsoft for Microsoft Office Word. Refer to the Microsoft Update Guide for CVE-2026-55124 for patch details.
  • Restrict access to sensitive documents or systems that use Microsoft Office Word until the patch is applied.
  • Monitor for unusual activity or unauthorized access attempts, particularly those involving local information disclosure.

Since the vulnerability allows local information disclosure, ensuring that only trusted users have access to systems running vulnerable versions of Microsoft Office Word can reduce risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55124. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart