Sceawere

Vulnerability Detail

CVE-2026-64904UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Type Confusion Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:51.323Z",
  "pubdate": "2026-08-11T17:18:51.323Z",
  "executiveSummary": "A type confusion vulnerability exists within Microsoft Office due to the improper handling and access of resources using incompatible types. This flaw allows an unauthorized local attacker to execute arbitrary code within the context of the current user. The vulnerability impacts Microsoft Office products and poses significant risk to system integrity and confidentiality. Successful exploitation enables unauthorized code execution on the targeted system. While specific remote exploitation vectors or specialized authentication requirements are not detailed in the base input, local access is a prerequisite for executing the attack payload. The implications of this vulnerability include potential complete compromise of the affected workstation if the execution context possesses elevated privileges. Remediation requires adherence to official vendor bulletins, application updates, and standard endpoint hardening practices to restrict unauthorized local code execution vectors.",
  "technicalDetails": "The vulnerability is fundamentally rooted in a type confusion weakness within Microsoft Office components. Type confusion occurs when a resource is created or initialized using one data type, but subsequently accessed or interpreted through an incompatible data type. This discrepancy typically arises from improper memory management, incorrect object casting, or logical flaws during the parsing of complex file formats processed by Microsoft Office.\nDuring the attack flow, a malicious local actor leverages the type confusion condition to induce unexpected application behavior. When the vulnerable component processes crafted input or interacts with manipulated internal objects, the system fails to adequately enforce type safety boundaries. Consequently, referencing an object via an incompatible type pointer can lead to out-of-bounds memory access, pointer corruption, or the misinterpretation of data structures as function pointers.\nAn unauthorized attacker with local access on the target system can exploit this programmatic oversight by staging a specially crafted document or application state designed to trigger the memory corruption sequence. Upon opening or processing the malicious construct, Microsoft Office incorrectly resolves the type-confused resource, causing the execution flow to be redirected to attacker-controlled memory locations. This manipulation facilitates the execution of arbitrary shellcode or payloads residing locally on the system.\nThe vulnerable component resides within the core processing and rendering engines of Microsoft Office. The exploitation mechanics rely on local execution vectors, meaning the attacker must be capable of executing code or deploying the trigger file within the local environment of the victim machine. The payload executes with the privileges of the user running the affected Microsoft Office instance. Post-exploitation impact includes unauthorized code execution, potential escalation of local privileges depending on the user context, and subsequent installation of secondary malware or persistence mechanisms within the local environment."
}
CVE-2026-64904: Microsoft Office Type Confusion Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere