« Volver al listado

CVE-2026-45466

Estado: AnalizadaBaja (3.3)—

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45466",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45466",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T13:40:28.513794Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft 365 Apps for Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.1",
              "lessThan": "https://aka.ms/OfficeSecurityReleases",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Office 365 for Mac",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "16.110.26061317",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Office LTSC 2021",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.1",
              "lessThan": "https://aka.ms/OfficeSecurityReleases",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Office LTSC 2024",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.0",
              "lessThan": "https://aka.ms/OfficeSecurityReleases",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Office LTSC for Mac 2021",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.1",
              "lessThan": "16.110.26061317",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Office LTSC for Mac 2024",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.0",
              "lessThan": "16.110.26061317",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-09T17:17:21.077",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en montículo en Microsoft Office Word permite a un atacante no autorizado divulgar información localmente."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "3259EBFE-AE2D-48B8-BE9A-E22BBDB31378"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "CD25F492-9272-4836-832C-8439EBE64CCF"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12418BDE-FA2E-4BBF-8E47-45C505399898"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "1D518075-3362-4D15-93B1-0E6C61518D16"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "1059BEC6-C30B-4F0F-A878-5267A21CBD85"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*",
              "vulnerable": true,
              "matchCriteriaId": "0DB3EBBF-E0C4-4D5A-8D22-107463AD1DE4"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "55A9AFDA-D77B-4CC7-ACE5-3A2ABDA257D8"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "8887D177-26A3-4008-89B6-50A9E9830F13"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*",
              "vulnerable": true,
              "matchCriteriaId": "589B470B-9C2E-41E2-A44D-D8CCB4D2F933"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}