PT-2026-4775 · Microsoft · Office

·

CVE-2026-21509

·

Published

2026-01-26

·

Updated

2026-09-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office 2016 Microsoft Office 2019 Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft 365 Apps for Enterprise
Description Microsoft Office contains a flaw where the application relies on untrusted inputs when making security decisions, allowing an unauthorized attacker to bypass local security features. Specifically, the issue involves a bypass of Object Linking and Embedding (OLE) security mechanisms. An attacker can exploit this by convincing a user to open a specially crafted document (such as RTF or DOC files), which can lead to arbitrary code execution on the system. In real-world incidents, the Russian state-sponsored group APT28 (Fancy Bear) has weaponized this flaw to deploy multi-stage infection chains involving loaders like SimpleLoader and backdoors such as NotDoor and BeardShell. The exploitation process often triggers a WebDAV connection to retrieve further payloads and may utilize Component Object Model (COM) hijacking to maintain persistence. The vulnerability is exploited by targeting the OLE component Shell.Explorer.1 with the CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.
Recommendations For Microsoft Office 2016, install security update KB5002713. For Microsoft Office 2019, update to Build 10417.20095 or newer. For Microsoft Office LTSC 2021, install the February 2026 security update. For Microsoft Office LTSC 2024, install the February 2026 security update. For Microsoft 365 Apps for Enterprise, apply the latest security updates via the automated update channel. As a temporary mitigation, restrict the use of the vulnerable OLE component by adding a registry key {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} under the COM Compatibility node of the appropriate Microsoft Office registry path and setting the Compatibility Flags DWORD value to 400.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00828
CVE-2026-21509

Affected Products

Office