2026年1月27日星期二

Microsoft Office Security Restriction Bypass Vulnerability

Microsoft Office Security Restriction Bypass Vulnerability

Release Date: 27 Jan 2026

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Microsoft Office. An attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.

 

Note:

CVE-2026-21509 is being exploited in the wild. Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. An attacker must send a user a malicious Office file and convince them to open it. Hence, the risk level is rated as Medium Risk.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Microsoft 365 Apps for Enterprise
  • Microsoft Office 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

  • Customers running Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect.
  • Customers running Office 2016 and 2019 are not protected until they install the security update. Customers on these versions can apply the registry keys described as follows to be immediately protected. Please refer to the below link for the steps.

Apply fixes or mitigations issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Jenkins 多個漏洞

Jenkins 多個漏洞 發佈日期: 2026年03月20日 風險: 中度風險 類型: 伺服器 - 互聯網應用伺服器 於 Jenkins 發現多...