By Abinaya
Publication Date: 2026-06-12 08:40:00
Microsoft released critical fixes for three closely related remote code execution (RCE) vulnerabilities in Microsoft Outlook and Word that stem from low‑level memory‑safety flaws in the Word rendering engine and its integration with Outlook Classic.
These bugs, tracked as CVE‑2026‑45456, CVE‑2026‑45458, and CVE‑2026‑47635, are rated Critical with a CVSS v3.1 base score of 8.4, reflecting high impact on confidentiality, integrity, and availability if exploited.
Although the CVSS vectors show a local attack vector (AV:L), Microsoft classifies them as remote code execution because a remote attacker can deliver malicious content over the network (for example, via email). At the same time, the actual exploit triggers locally when Office processes the content.
Microsoft Outlook and Word RCE Flaws
All three vulnerabilities are rooted in unsafe memory handling within the Office document parsing pipeline.
CVE‑2026‑45456 and CVE‑2026‑47635 involve type…



