Sceawere

Vulnerability Detail

CVE-2026-70319UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:09.493Z",
  "pubdate": "2026-08-11T17:19:09.493Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw residing within Microsoft Office Word. The primary security impact of this vulnerability is local information disclosure, which compromises the confidentiality of sensitive data stored on the affected system. The affected product is Microsoft Office Word. The risk implication centers on unauthorized data exposure, potentially granting an attacker access to local files or memory contents that should otherwise be restricted. Attacker capabilities are limited to local exploitation, requiring the execution of a specially crafted document or interaction with the vulnerable application. Based on the provided context, specific remote network vectors or specialized authentication requirements beyond standard local execution parameters are not explicitly mandated for successful exploitation. Mitigation requires applying official vendor patches or updates as soon as they become available to correct the underlying input validation mechanism.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient or improper input validation within the parsing logic of Microsoft Office Word. When processing malformed or maliciously constructed input data structures, the application fails to properly sanitize or validate the boundaries and contents of the parsed elements. This improper handling of input allows an unauthorized local attacker to induce anomalous application behavior during document rendering or processing.\nThe exploitation method relies on supplying a specially crafted file to the vulnerable component of Microsoft Office Word. When a user opens or interacts with the malicious file, the application processes the malformed structures incorrectly. Because of the improper input validation, the parsing routine interacts with memory or local file resources in an unintended manner, leading to unauthorized read operations.\nThe attack flow proceeds as follows: First, the attacker creates a malicious document containing targeted input anomalies designed to trigger the validation failure. Second, the victim opens the file using Microsoft Office Word on the local system. Third, as the application parses the document's internal structures, the flawed validation logic fails to catch the malformed data. Finally, the parsing engine inadvertently exposes sensitive local information, which can then be captured or accessed by the attacker.\nThe vulnerable component is the input parsing and validation subsystem within Microsoft Office Word. The affected versions encompass those deployments lacking the necessary security updates to address this specific input validation weakness. Regarding authentication and privilege requirements, the attack requires local access to the target system and the ability to cause the execution or parsing of the malicious file within the context of the local user session. The network exposure is strictly local, as the vulnerability does not inherently provide a remote exploitation vector based on the provided description. The post-exploitation impact is limited to local information disclosure, wherein the confidentiality of affected data is breached without necessarily granting immediate remote code execution or persistence capabilities."
}
CVE-2026-70319: Microsoft Office Word Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere