CVE-2026-45649: Office for Android Spoofing Vulnerability

Overview

Severity
High (CVSS 7.1)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Jun
Released
2026-06-09
Last Updated
2026-06-19
EPSS Score
0.42% (percentile: 34.3%)

Description

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send a user a malicious Office file and convince them to open it. Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. Are the updates for Microsoft Word, PowerPoint, Excel for Android currently available? Yes. As of June 15, 2026, the security update for Microsoft Word, PowerPoint, Excel for Android are available. Customers running Microsoft Word, PowerPoint, Excel for Android should ensure the update is installed to be protected from this vulnerability.

Affected Products (3)

Microsoft Office

  • Microsoft Excel for Android
  • Microsoft PowerPoint for Android

Apps

  • Microsoft Word for Android

Security Updates (3)

Acknowledgments

<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>

Revision History

  • 2026-06-09: Information published.
  • 2026-06-19: Microsoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.