External Control of File Name or Path in Microsoft Office - CVE-2026-62804
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code locally.
The vulnerability exists due to external control of file name or path in Microsoft Office Word when opening a malicious Office file. A remote attacker can send a malicious Office file and convince a user to open it to execute code locally.
The Preview Pane is not an attack vector.