CVE-2026-55142
Analyzed Analyzed - Analysis Complete

Numeric Truncation Error in Microsoft Office Word

Vulnerability report for CVE-2026-55142, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft word 2016
microsoft word 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-197 Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55142 is a numeric truncation error in Microsoft Office Word. This vulnerability allows an unauthorized attacker to disclose information locally on the affected system.

A numeric truncation error typically occurs when a value is improperly shortened or rounded, leading to unexpected behavior. In this case, it can be exploited to access sensitive information that should not be available to the attacker.

The vulnerability is classified with a CVSS base score of 5.5, indicating a medium severity level. The attack vector is local (AV:L), meaning the attacker must have access to the system, and the impact is limited to information disclosure (C:H).

Detection Guidance

The provided context does not specify methods or commands to detect this vulnerability on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office Word or monitoring for unusual local information disclosure behavior, but no specific detection steps are outlined in the available resources.

To identify vulnerable systems, you may need to verify the installed version of Microsoft Office Word against the patched versions released by Microsoft. Refer to the Microsoft Update Guide for CVE-2026-55142 for version details and patch information.

Impact Analysis

If you use Microsoft Office Word and this vulnerability is exploited, an attacker could gain access to sensitive information stored or processed on your local system.

  • Local information disclosure: The attacker could read files or data that are accessible to the Word application but should not be exposed.
  • Potential for further attacks: The disclosed information might include credentials, personal data, or other sensitive details that could be used in additional attacks.

Since the attack requires local access, the risk is higher in environments where multiple users share the same system or where physical security is not strictly controlled.

Compliance Impact

This vulnerability could impact compliance with several standards and regulations, depending on the type of data processed or stored by Microsoft Office Word.

  • GDPR: If the disclosed information includes personal data of EU citizens, this could be considered a data breach. Organizations may be required to report the incident and could face fines if they failed to implement adequate security measures.
  • HIPAA: If the information disclosed includes protected health information (PHI), this could violate HIPAA regulations. Covered entities and business associates would need to report the breach and could face penalties.
  • Other regulations: Depending on the industry, other standards like PCI DSS (for payment data) or sector-specific regulations may also be affected if sensitive data is exposed.

Organizations should assess whether the vulnerability could lead to unauthorized access to regulated data and take appropriate steps to mitigate the risk, such as applying patches or implementing compensating controls.

Mitigation Strategies

Immediate steps to mitigate this vulnerability include:

  • Apply the latest security updates provided by Microsoft for Microsoft Office Word. Refer to the Microsoft Update Guide for CVE-2026-55142 for the specific patch.
  • Restrict access to sensitive documents or systems to minimize the risk of local information disclosure.
  • Monitor Microsoft's official communications for any additional guidance or workarounds related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55142. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart