CVE-2026-56192
Analyzed Analyzed - Analysis Complete

Out-of-bounds Read in Microsoft Office

Vulnerability report for CVE-2026-56192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft office_2019 *
microsoft office_2019 *
microsoft office_2016 *
microsoft office_2016 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-56192 is an out-of-bounds read vulnerability in Microsoft Office. This means that the software reads data beyond the intended boundary, which can allow an unauthorized attacker to access sensitive information stored in memory.

The vulnerability is classified as an information disclosure issue, meaning its primary impact is the exposure of confidential data rather than direct code execution or system compromise.

According to the CVSS v3.1 score, the attack vector is local (AV:L), meaning the attacker must have access to the target system. The attack complexity is low (AC:L), and no privileges are required (PR:N), but user interaction is required (UI:R), such as opening a malicious file.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-56192 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office or using security tools that can identify out-of-bounds read vulnerabilities in installed software.

To detect vulnerable versions of Microsoft Office, you can check the installed version using the following steps:

  • Open any Microsoft Office application (e.g., Word, Excel).
  • Go to 'File' > 'Account' or 'Help' (depending on the version).
  • Note the version number and build number displayed.

Compare the installed version with the patched versions listed in Microsoft's official security update guide for CVE-2026-56192. If the installed version is outdated, the system may be vulnerable.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Exposure of sensitive information: An attacker could exploit this flaw to read confidential data from your system, such as documents, credentials, or other sensitive files stored in memory.
  • Local access requirement: Since the attack vector is local, the attacker must already have some level of access to your system, either physically or through another exploit.
  • User interaction required: The attacker would need you to open a specially crafted file, such as a malicious Office document, to trigger the vulnerability.

While the vulnerability does not allow for remote code execution or direct system takeover, the disclosure of sensitive information can still lead to further attacks or data breaches.

Compliance Impact

This vulnerability can affect compliance with common standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a data breach. Under GDPR, organizations must protect personal data and report breaches within 72 hours if they pose a risk to individuals' rights and freedoms.
  • HIPAA (Health Insurance Portability and Accountability Act): If the disclosed information includes protected health information (PHI), this vulnerability could result in a HIPAA violation. Covered entities must implement safeguards to protect PHI and report breaches involving unsecured PHI.
  • Other regulations: Depending on the industry and type of data exposed, this vulnerability could also impact compliance with standards like PCI DSS (for payment card data) or sector-specific regulations.

Failure to address this vulnerability could result in non-compliance, potential fines, and reputational damage if sensitive data is exposed.

Mitigation Strategies

To mitigate CVE-2026-56192, apply the latest security updates provided by Microsoft for Microsoft Office. The following steps are recommended:

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-56192 to download and install the latest patches.
  • Ensure all Microsoft Office applications are updated to the latest version using the built-in update mechanism or by downloading updates from the official Microsoft website.
  • If immediate patching is not possible, restrict access to Microsoft Office applications to trusted users only and avoid opening files from untrusted sources.
  • Monitor Microsoft's official communications for additional guidance or workarounds related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart