
[CIVN-2026-0283] Remote Code Execution Vulnerability in Microsoft Office
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Microsoft Office
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Office
Overview
A vulnerabilities has been reported in Microsoft Office which could allow an attacker to execute arbitrary code in the context of the current user on the affected system.
Target Audience:
All end-user organizations and individuals using Microsoft Office product.
Risk Assessment:
High risk of remote code execution, unauthorized access, and potential system compromise.
Impact Assessment:
Potential for data theft, execution of malicious code in the context of the current user, and unauthorized actions on the affected system.
Description
Microsoft Office is a widely used productivity suite that includes applications for document creation, data analysis, presentations, and collaboration. It is commonly deployed across enterprise and individual environments.
A remote code execution vulnerability exists in Microsoft Office components due to the deserialization of untrusted data. An authorized attacker could exploit this vulnerability over a network by sending specially crafted data to a vulnerable server.
Successful exploitation could allow the attacker to execute arbitrary code on the affected system, potentially leading to unauthorized access, data manipulation, and compromise of the affected environment.
Solution
Apply appropriate updates as mentioned by the vendor:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
CVE Name
CVE-2026-45659
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogPQQACgkQ3jCgcSdc
ys9wQg/8C6nGOO0MODDoTt6C3NvFEQn8Q9l4smK9TDHMrGlIyKMFaYYoSjMpZBtL
ZOF2bmPOQYxVt6JMxhFzmKS6KArAUxUTqJNWuM5a21bMQZaURWeOx/SheOihEXr8
8SiN1e/fuTfA3iqxxHuUlEPpoZTggTraz45abX9YJOJZnDwmN3mAdLmOTq5AqIk7
JTIQREoXBvIqyZKGi38G8dr1HfxE3qBavlJVLNdDJ3fBoqpAC8MzuoqVuCGtiViL
aKy1hyX1m3zMxkx1QWpRxK5NERS89y9QSZrHHcjHW6hhtKIwo46B9w1b5ic2trzk
HBb8UT9BEfDdxRVjVhlwZIFnsivICGYQaWkAnph4dzmSXBOQBaTCHieHotaf1/bG
Pgvb3RqbMit5J5JnS43gvGynSZvdf28+XR4tSf07IE7E4NGMppoxTeAyEceEHexc
uLJeLSySpbtRrDpNtpJa4wCdhc1rj5TOpVAjQ5s8CamJbXCH41GStET/SKM5gf4P
DGtS1nmqy4x/O28S4A6G60/Jf9FhhbDrB31aimb6WDTiRg2aMEUkhEv/QgboGt96
USbxdJpjM49n2KCKGQMfCom+F5DsTvKy9ate9ue/znq8Z28k0nUW5k/sAJaeWaVF
Ebqzm0pdiWQHF6Mjbr9M/Kpo5Y7lPfNZ+A8KMhuVHtmaYxzAVMc=
=bVbZ
—–END PGP SIGNATURE—–


