High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2026-20944
High
Low
Medium
High
Critical
8.4
CVSS Score
Published: Jan 13, 2026
Last Modified: Jan 16, 2026
Vulnerability Description
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H
Known Affected Software
3 configuration(s) from 1 vendor(s)
office_long_term_servicing_channel
Version:
2024
CPE:
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
office_long_term_servicing_channel
Version:
2021
CPE:
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:x86:*
365_apps
Version:
-
CPE:
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.
Severity Details
8.4
out of 10.0
High
Key Information
- Published Date
- January 13, 2026
