CVE-2026-45649: Office for Android Spoofing Vulnerability
Overview
- Severity
- High (CVSS 7.1)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
- Category
- Spoofing
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2026-Jun
- Released
- 2026-06-09
- Last Updated
- 2026-06-19
- EPSS Score
- 0.42% (percentile: 34.3%)
Description
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Are the updates for Microsoft Word, PowerPoint, Excel for Android currently available?
Yes. As of June 15, 2026, the security update for Microsoft Word, PowerPoint, Excel for Android are available. Customers running Microsoft Word, PowerPoint, Excel for Android should ensure the update is installed to be protected from this vulnerability.
Affected Products (3)
Microsoft Office
- Microsoft Excel for Android
- Microsoft PowerPoint for Android
Apps
- Microsoft Word for Android
Security Updates (3)
Acknowledgments
<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>
Revision History
- 2026-06-09: Information published.
- 2026-06-19: Microsoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.