Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft microsoft 365
Microsoft office 2016 |
|
| CPEs | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:* cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:* cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:* cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft microsoft 365
Microsoft office 2016 |
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Title | Microsoft Outlook and Word Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft 365 Apps Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft office 365 Microsoft office Macos 2021 Microsoft office Macos 2024 Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 Microsoft word 2016 |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:* cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:* cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Apps Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft office 365 Microsoft office Macos 2021 Microsoft office Macos 2024 Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 Microsoft word 2016 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published: 2026-06-09T17:04:36.685Z
Updated: 2026-06-10T17:53:30.486Z
Reserved: 2026-05-12T16:06:43.097Z
Link: CVE-2026-45456
Updated: 2026-06-10T10:29:47.438Z
Status : Analyzed
Published: 2026-06-09T17:17:19.790
Modified: 2026-06-11T18:40:05.357
Link: CVE-2026-45456
No data.