Microsoft Office Spoofing Vulnerability Allowing Unauthorized Local Access

Vulnerability

A vulnerability in Microsoft Office products, including Excel and Word for Android, as well as Office LTSC for Mac 2021 and 2024, has been identified. This vulnerability involves improper access control, which allows an unauthorized attacker to perform spoofing actions locally. The issue arises from a lack of adequate access controls, enabling spoofing opportunities within the affected applications.

Impact

Exploitation of this vulnerability could lead to unauthorized spoofing actions within the affected Microsoft Office applications.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. Instructions for applying the update are available in the release notes linked in the Knowledge Base Articles for each affected product.

Added: May 12, 2026, 7:04 PM
Updated: May 12, 2026, 7:04 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.