微软 Office Word 中存在不当输入验证漏洞,攻击者可利用该漏洞通过网络泄露信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office 2019 | 19.0.0< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office 365 for Mac | 1.0.0< 16.112.26081010 |
affected |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office LTSC 2024 | 16.0.0< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office LTSC for Mac 2021 | 16.0.1< 16.112.26081010 |
affected |
| Microsoft | Microsoft Office LTSC for Mac 2024 | 16.0.0< 16.112.26081010 |
affected |
| Microsoft | Microsoft Word 2016 | 16.0.1< 16.0.5565.1000 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office 2019 | 19.0.0 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office 365 for Mac | 1.0.0 ~ 16.112.26081010 | - |
|
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office LTSC 2024 | 16.0.0 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office LTSC for Mac 2021 | 16.0.1 ~ 16.112.26081010 | - |
|
| Microsoft | Microsoft Office LTSC for Mac 2024 | 16.0.0 ~ 16.112.26081010 | - |
|
| Microsoft | Microsoft Word 2016 | 16.0.1 ~ 16.0.5565.1000 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65801 | 10.0 CRITICAL | Microsoft Exchange Online Elevation of Privilege Vulnerability |
| CVE-2026-69555 | 10.0 CRITICAL | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-69836 | 10.0 CRITICAL | Microsoft Entra ID Remote Code Execution Vulnerability |
| CVE-2026-65770 | 10.0 CRITICAL | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
| CVE-2026-65816 | 10.0 CRITICAL | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-68789 | 9.9 CRITICAL | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-69851 | 9.9 CRITICAL | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-68782 | 9.9 CRITICAL | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-63509 | 9.9 CRITICAL | Microsoft Fabric Elevation of Privilege Vulnerability |
| CVE-2026-69400 | 9.6 CRITICAL | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-62834 | 9.3 CRITICAL | Azure Data Factory Elevation of Privilege Vulnerability |
| CVE-2026-66309 | 9.1 CRITICAL | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-66800 | 8.6 HIGH | Azure Data Factory Information Disclosure Vulnerability |
| CVE-2026-69519 | 8.6 HIGH | Azure Stack HCI Information Disclosure Vulnerability |
| CVE-2026-69558 | 8.6 HIGH | Microsoft Partner Center Information Disclosure Vulnerability |
| CVE-2026-69419 | 8.5 HIGH | Azure Data Manager for Energy Remote Code Execution Vulnerability |
| CVE-2026-69543 | 8.5 HIGH | Azure Virtual Machines Elevation of Privilege Vulnerability |
| CVE-2026-69855 | 7.7 HIGH | Microsoft Copilot in Azure Information Disclosure Vulnerability |
| CVE-2026-55013 | 7.1 HIGH | Windows Remote Help Defense Spoofing Vulnerability |
| CVE-2026-55015 | 5.5 MEDIUM | Microsoft Remote Help Denial of Service Vulnerability |
No comments yet