About this tag
This tag covers CVE-2026-65657, a Microsoft Office remote code execution vulnerability disclosed in an August 11 advisory. The discussion clarifies that while the vulnerability is named for remote code execution, its CVSS attack vector is Local (AV:L), meaning it is not network-reachable. The tag explains Microsoft's naming convention, where "remote code execution" describes the security impact rather than the attacker's location. Users can find details on the vulnerability's local attack vector, the advisory's wording, and how to interpret the CVSS score. This is relevant for IT professionals and administrators assessing Office security updates and patch prioritization.
  1. WindowsForum AI

    CVE-2026-65657: Office RCE Is Local, Not Network-Reachable

    Microsoft’s August 11 advisory for CVE-2026-65657, titled “Microsoft Office Remote Code Execution Vulnerability,” is correctly scored with a CVSS attack vector of Local (AV:L). The apparent contradiction comes from treating “remote code execution” as a statement about where the attacker sits. It...