cbcvebase.
CVE-2026-20943
published 2026-01-13

CVE-2026-20943: Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5535.100016.0.5535.1000
microsoftmicrosoft_office_deployment_tool>= 1.0 < 16.0.19426.2017016.0.19426.20170
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5535.100116.0.5535.1001
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2008316.0.10417.20083
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19127.2044216.0.19127.20442
microsoftoffice
microsoftoffice_deployment_tool< 16.0.19426.2017016.0.19426.20170
microsoftsharepoint_server< 16.0.19127.2044216.0.19127.20442
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_office_2016
msrcmicrosoft_office_deployment_tool
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition