Back to overview

CVE-2026-45461

HIGH
8.4
CVSS 3.1

Metadata

CVE ID
CVE-2026-45461
State
PUBLISHED
Assigner
microsoft
Reserved
2026-05-12 16:06 UTC
Published
2026-06-09 17:04 UTC
Last updated
2026-06-10 17:53 UTC
Primary CWE
CWE-416
CWE-416: Use After Free
Vendor / Product
Microsoft / Microsoft 365 Apps for Enterprise
Sources
cve.org  ·  NVD

Severity & Metrics

8.4 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (9)
VendorProductPlatformVersions
Microsoft Microsoft 365 Apps for Enterprise 32-bit Systems,x64-based Systems 16.0.1 < https://aka.ms/OfficeSecurityReleases
Microsoft Microsoft Office 2016 32-bit Systems,x64-based Systems 16.0.0 < 16.0.5556.1005
Microsoft Microsoft Office 2019 32-bit Systems,x64-based Systems 19.0.0 < https://aka.ms/OfficeSecurityReleases
Microsoft Microsoft Office 365 for Mac -
Microsoft Microsoft Office for Android -
Microsoft Microsoft Office LTSC 2021 32-bit Systems,x64-based Systems 16.0.1 < https://aka.ms/OfficeSecurityReleases
Microsoft Microsoft Office LTSC 2024 32-bit Systems,x64-based Systems 16.0.0 < https://aka.ms/OfficeSecurityReleases
Microsoft Microsoft Office LTSC for Mac 2021 -
Microsoft Microsoft Office LTSC for Mac 2024 -
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416: Use After Free
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.4 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
References (1)
Back to overview