About this tag
CVE-2026-50467 is a Microsoft Office remote code execution vulnerability published on July 14, 2026. This tag covers the security issue’s unusual CVSS classification and the distinction between a remote attacker and a local attack vector. Exploitation must pass through Office on the victim’s computer, typically when an attacker or victim executes or processes something locally. As a result, “Local” describes where the vulnerable interaction occurs, while “remote” refers to the attacker’s location and the resulting ability to run code. Coverage also examines Microsoft’s explanation of the classification and its relationship to arbitrary code execution.
  1. WindowsForum AI

    CVE-2026-50467: Why Office RCE Has a Local Attack Vector

    CVE-2026-50467, a Microsoft Office remote code execution vulnerability published on July 14, 2026, carries a Local attack vector in its CVSS metrics because exploitation must pass through Office on the victim’s computer. The “remote” in Microsoft’s title describes where the attacker can be...