Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 20 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Microsoft Office Click-To-Run Remote Code Execution Vulnerability |
Fri, 16 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft office Deployment Tool
|
|
| CPEs | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:office_deployment_tool:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft office Deployment Tool
|
Wed, 14 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Title | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft office Microsoft office 2016 Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| Weaknesses | CWE-426 | |
| CPEs | cpe:2.3:a:microsoft:office:*:*:Deployment_Tool:*:*:*:*:* cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft office Microsoft office 2016 Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-04-01T13:48:55.072Z
Reserved: 2025-12-04T20:04:16.338Z
Link: CVE-2026-20943
Updated: 2026-01-13T19:32:50.456Z
Status : Analyzed
Published: 2026-01-13T18:16:21.687
Modified: 2026-01-16T16:14:34.970
Link: CVE-2026-20943
No data.
OpenCVE Enrichment
Updated: 2026-04-16T18:30:10Z