Insufficiently protected credentials in Microsoft Office - CVE-2026-64918

 

Insufficiently protected credentials in Microsoft Office - CVE-2026-64918

Published: September 8, 2026


Vulnerability identifier: #VU147489
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64918
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose NTLM hashes.

The vulnerability exists due to insufficiently protected credentials in Microsoft Office when a user interacts with a file. A remote attacker can induce a user to interact with a file to disclose NTLM hashes.

Interactions that trigger the leakage include opening the parent folder in Explorer, clicking, dragging, or deleting the file.


Affected software

Microsoft Office

How to mitigate CVE-2026-64918

Install security update from vendor's website.

Microsoft Office - addressed in versions 16.0.5569.1003, 16.0.17932.20960

External References

Related Security Bulletins