PT-2026-4775 · Microsoft · Office
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office LTSC 2021
Microsoft Office LTSC 2024
Microsoft 365 Apps for Enterprise
Description
Microsoft Office contains a flaw where the application relies on untrusted inputs when making security decisions, allowing an unauthorized attacker to bypass local security features. Specifically, the issue involves a bypass of Object Linking and Embedding (OLE) security mechanisms. An attacker can exploit this by convincing a user to open a specially crafted document (such as RTF or DOC files), which can lead to arbitrary code execution on the system. In real-world incidents, the Russian state-sponsored group APT28 (Fancy Bear) has weaponized this flaw to deploy multi-stage infection chains involving loaders like SimpleLoader and backdoors such as NotDoor and BeardShell. The exploitation process often triggers a WebDAV connection to retrieve further payloads and may utilize Component Object Model (COM) hijacking to maintain persistence. The vulnerability is exploited by targeting the OLE component
Shell.Explorer.1 with the CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.Recommendations
For Microsoft Office 2016, install security update KB5002713.
For Microsoft Office 2019, update to Build 10417.20095 or newer.
For Microsoft Office LTSC 2021, install the February 2026 security update.
For Microsoft Office LTSC 2024, install the February 2026 security update.
For Microsoft 365 Apps for Enterprise, apply the latest security updates via the automated update channel.
As a temporary mitigation, restrict the use of the vulnerable OLE component by adding a registry key
{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} under the COM Compatibility node of the appropriate Microsoft Office registry path and setting the Compatibility Flags DWORD value to 400.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office