CVE-2026-64904

365_apps: Access of Resource Using Incompatible Type ('Type Confusion') (CVE-2026-64904)

Beschreibung

Der Zugriff auf eine Ressource mit einem nicht kompatiblen Typ ('Typverwirrung') in Microsoft Office ermöglicht es einem unbefugten Angreifer, lokal Code auszuführen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.8
Quelle: nvd-v3
22.8 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.3 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 17:06 UTC
CWE-843

Weakness-Klassen (CWE)

  • CWE-843Base

    Access of Resource Using Incompatible Type ('Type Confusion')

    The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-08-14 15:10 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* *cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* *cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:* *cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:* *cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:* *cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:* *cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904 Types: Vendor Advisory
  2. CVE Modified2026-08-11 19:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-64904","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
    • Affected: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+4)
    • Description: Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
    • CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    • CWE: CWE-843

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • microsoft

    365_apps

  • microsoft

    microsoft_365

  • microsoft

    office_2019

  • microsoft

    office_2021

  • microsoft

    office_2024

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-64904