You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-45461
About this tag
CVE-2026-45461 is a Critical Microsoft Office remote code execution vulnerability disclosed on June 9, 2026. Although its CVSS vector lists the attack vector as local (AV:L), Microsoft classifies it as an RCE because exploitation typically involves code running on the victim's machine via hostile files, previews, or local parsing paths. This distinction reflects a difference between Microsoft's impact categorization and CVSS technical attack vector definitions. For administrators, the vulnerability represents a remote-style risk even though the network is not the direct attack surface. Discussions on WindowsForum cover the practical implications for defending Office environments against such threats.
Microsoft disclosed CVE-2026-45461 on June 9, 2026 as a Critical Microsoft Office remote code execution vulnerability, even though its CVSS vector lists the attack vector as local because exploitation depends on code being run on the victim’s machine. That wording is not a contradiction so much...