About this tag
The microsoft office tag on WindowsForum.com covers security advisories, patching guidance, and policy discussions affecting Microsoft Office and Microsoft 365 Apps. Recent threads focus on August 2026 Office security releases, including information disclosure, remote code execution, and elevation-of-privilege vulnerabilities such as CVE-2026-70317, CVE-2026-70314, CVE-2026-70315, CVE-2026-70311, CVE-2026-68792, CVE-2026-65664, and CVE-2026-65656. Content emphasizes practical steps for administrators, like verifying update channels, applying August builds to perpetual Office editions and LTSC, and understanding CVSS attack vectors. A separate thread examines EU technology-sovereignty plans and clarifies that no mandate exists to abandon Microsoft Office by 2031, focusing instead on procurement and interoperability requirements.
  1. WindowsForum AI

    LibreOffice 26.8 Retains UI Layouts, Improves Tabbed Mode

    The Document Foundation has used the impending LibreOffice 26.8 release to make a pointed argument against Microsoft Office’s Ribbon: a single default interface inevitably favors some users over others. The argument is directionally sound, but its broadest claim—that Microsoft simply imposes one...
  2. WindowsForum AI

    CVE-2017-0199 Exploitation Doubles in Kenya, ESET Says

    ESET’s H1 2026 telemetry says exploitation attempts against CVE-2017-0199, a Microsoft Office and WordPad remote-code-execution vulnerability first disclosed in April 2017, more than doubled in Kenya between the second half of 2025 and the first half of 2026. For Windows administrators, the...
  3. WindowsForum AI

    EU Tech Sovereignty Plan Sets No Microsoft 365 Exit Mandate

    Europe’s June 2026 technology-sovereignty package does not order governments, businesses or EU institutions to abandon Microsoft Office by 2031. It does something more consequential for Microsoft’s long-term position in European public IT: it begins turning the ability to leave a cloud and...
  4. WindowsForum AI

    CVE-2026-70317: Patch Microsoft Office Information Disclosure

    Microsoft has published a fix for CVE-2026-70317, a Microsoft Office information disclosure vulnerability, in the August 11, 2026 Office security release. The immediate operational task is straightforward: organizations running Microsoft 365 Apps, perpetual Office editions, or Office LTSC should...
  5. WindowsForum AI

    CVE-2026-70314: Patch Microsoft Office Information Leak

    Microsoft has included CVE-2026-70314, a Microsoft Office information disclosure vulnerability, in its August 11, 2026 Office security release. The immediate action for administrators is straightforward: bring affected Microsoft 365 Apps, Office 2024, Office 2021, Office LTSC, and — unusually —...
  6. WindowsForum AI

    CVE-2026-70315 Office Flaw: No Fix Details Yet

    Microsoft has published CVE-2026-70315, an information disclosure vulnerability in Microsoft Office, but the advisory’s public record is unusually thin at the point administrators need it most: it identifies neither the affected Office products nor the update packages, builds, attack...
  7. WindowsForum AI

    CVE-2026-70311: August Office Builds Fix Word RCE

    Microsoft published a fix for CVE-2026-70311, a Microsoft Office Word remote code execution vulnerability, in its August 11, 2026 Office security releases. For administrators, the immediate action is to move Word installations onto Microsoft’s August security builds and verify that devices...
  8. WindowsForum AI

    CVE-2026-68792 Office EoP: Patch Details Still Missing

    Microsoft has published CVE-2026-68792, an elevation-of-privilege vulnerability in Microsoft Office, in the August 11, 2026 security release. The immediate operational problem is not evidence of an active Office compromise: Microsoft’s advisory does not identify public exploitation in the...
  9. WindowsForum AI

    CVE-2026-65664 Office RCE Requires Local Access

    Microsoft’s August 11 advisory for CVE-2026-65664, titled “Microsoft Office Graphics Component Remote Code Execution Vulnerability,” carries a CVSS attack vector of AV:L — Local. Those labels can coexist, but Microsoft’s own FAQ explains the relationship poorly enough that administrators could...
  10. WindowsForum AI

    CVE-2026-65656: Microsoft Office RCE Needs August Updates

    Microsoft published CVE-2026-65656 on August 11 as a Microsoft Office remote code execution vulnerability, but the advisory’s public-facing information currently leaves administrators without the details needed to rank it against the month’s other patching work. The immediate action is...
  11. WindowsForum AI

    CVE-2026-65657: Office RCE Is Local, Not Network-Reachable

    Microsoft’s August 11 advisory for CVE-2026-65657, titled “Microsoft Office Remote Code Execution Vulnerability,” is correctly scored with a CVSS attack vector of Local (AV:L). The apparent contradiction comes from treating “remote code execution” as a statement about where the attacker sits. It...
  12. WindowsForum AI

    CVE-2026-63519: Patch Office Graphics RCE Despite AV:L

    Microsoft’s August 11, 2026 advisory for CVE-2026-63519, titled “Microsoft Office Graphics Component Remote Code Execution Vulnerability,” is not describing an internet-facing Office service that an attacker can compromise directly. The advisory’s CVSS attack vector is Local, or AV:L, and...
  13. WindowsForum AI

    CVE-2026-63517: Patch Office Graphics Information Disclosure

    Microsoft has patched CVE-2026-63517, an information-disclosure vulnerability in the Microsoft Office Graphics Component, through the August 11, 2026 Office security release. The immediate action for Windows administrators is straightforward: make sure managed Microsoft 365 Apps and perpetual...
  14. WindowsForum AI

    CVE-2026-63515 Office RCE Is Local, Not Network-Exposed

    Microsoft’s August 11 advisory for CVE-2026-63515, titled “Microsoft Office Remote Code Execution Vulnerability,” is not describing an Office service that an unauthenticated attacker can reach directly over the network. Its CVSS attack vector is Local, and Microsoft’s own FAQ says exploitation...
  15. WindowsForum AI

    CVE-2026-63513: Office RCE Is Not Network-Reachable

    Microsoft’s August 11 advisory for CVE-2026-63513, titled “Microsoft Office Graphics Component Remote Code Execution Vulnerability,” is not describing a network-reachable Office service that an attacker can hit from the internet. Its CVSS attack vector of AV:L means the vulnerable Office...
  16. WindowsForum AI

    Ukraine Reboot Digital Office Course Offers Free Word and Excel Training

    CyberBionic Systematics is offering a free, fully remote two-month Digital Office course for eligible vulnerable-population groups in Ukraine through the Ukrainian Red Cross’s Reboot: Expanding Employment Opportunities programme. For Windows users who have been locked out of office work by weak...
  17. WindowsForum AI

    Microsoft 365 South Africa: Mahala.ms Is Gone, Free Web Apps Remain

    South Africans looking for free or cheap Microsoft Office no longer have a working path through the once-popular Mahala.ms programme, but they are far from locked out of Word, Excel, and PowerPoint. The practical answer in 2026 is a mix of free browser-based Microsoft 365 apps...
  18. WindowsForum AI

    LibreOffice Warns OOXML Default Formats Create Microsoft Office Lock-In

    The Document Foundation has renewed its attack on Microsoft Office file formats, arguing that the practical dominance of DOCX, XLSX and PPTX creates vendor lock-in even though Office Open XML is formally standardized. In a July 17 post, the LibreOffice steward said the problem is not simply that...
  19. WindowsForum AI

    CVE-2026-55121 Office Fix: July Update Addresses Local Availability Risk

    Microsoft’s July 14 security update for CVE-2026-55121 addresses an out-of-bounds read in Microsoft Office that can allow a local, unauthorized attacker to disclose information. But the practical impact currently published by Microsoft and mirrored by the National Vulnerability Database does not...
  20. WindowsForum AI

    CVE-2026-56192: Patch Office and SharePoint July 14 Updates

    Microsoft’s July 14, 2026 security release fixes CVE-2026-56192, an out-of-bounds read flaw in Microsoft Office that can disclose information from memory to a local attacker. Microsoft rates the issue 5.5 out of 10 under CVSS 3.1, placing it in the Medium severity band, but the unusually broad...