PT-2026-88013 · Microsoft · 365 Apps+12
CVE-2026-78509
·
Publicado
2026-09-08
·
Atualizado
2026-09-12
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
This Microsoft Patch Tuesday, among with the historical 974 (!) bugs patched, I contributed three.
-
Microsoft Word Remote Code Execution Vulnerability (CVE-2026-78510) * https://t.co/7UyCIwJTji
-
Microsoft Office Outlook Remote Code Execution Vulnerability (CVE-2026-78509) https://t.co/Nn3oKfDPL4
-
Microsoft Office Word Remote Code Execution Vulnerability (CVE-2026-78507) https://t.co/PGTHsWEHEm
For me, the most notable one is the CVE-2026-78510, the Microsoft Security Update Guide page's title is quite misleading as it didn't even say it affects Outlook. In fact, it's a zero-click RCE (or someone like to call it "half-click") on Microsoft Outlook affecting the Preview Pane, means the bug could be triggered as long as the user previews or opens the email on Outlook. I'm communicating with MSRC to hopefully address the misleading webpage. I recommend patching it sooner rather than later.
Btw, if you're worrying about potential Outlook zero-click/half-click 0day attacks, I've put significant efforts in my @EXPMON system (https://t.co/NKqtbTEmVW) where it should be good at detecting such advanced attacks. It accepts email formats (.msg, .eml) and it checks deeply for various attack vectors!
#PatchTuesday #OfficeSecurity #Outlook #zeroday #0day #EmailSecurity
Correção
RCE
DoS
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
365 Apps
365 Apps For Enterprise
Office 2019
Office 365 For Mac
Office Ltsc 2021
Office Ltsc 2024
Office Ltsc For Mac 2021
Office Ltsc For Mac 2024
Office Word
Word 2016
365
Office 2021
Office 2024