VDB

GCVE-110-NCSC-2026-10

GCVE-110-NCSC-2026-10
Advisory PublishedCVSS 7.0/10
Vulnetix · Advisory published January 13, 2026
An untrusted search path vulnerability in Microsoft Office allows an attacker to execute unauthorized local code by exploiting the way Office handles file paths.

Weaknesses (CWE)

CWE-426Untrusted Search PathCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-502Deserialization of Untrusted DataCWE-822Untrusted Pointer DereferenceCWE-918Server-Side Request Forgery (SSRF)CWE-416Use After FreeCWE-125Out-of-bounds ReadCWE-122Heap-based Buffer OverflowCWE-20Improper Input ValidationCWE-284Improper Access Control

Risk Scores

CVSS 3.1
7.0/10
High · CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›