CyberRota Analysis
AI-GeneratedMicrosoft Office is vulnerable to a command injection flaw that enables authorized attackers to elevate their privileges locally. This high-severity vulnerability (CVSS 7.8) poses a significant risk to users who rely on Office for sensitive tasks. Organizations using Microsoft Office should prioritize patching this vulnerability to mitigate potential exploitation.
CVE
CVE-2026-68792
Severity
HIGH
CVSS
7.8
EPSS
0.25%
Microsoft Office
Original NVD Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
Related CVEs
Other vulnerabilities affecting the same vendor(s)