PT-2026-4775 · Microsoft · Office

Oruga00

+1

·

Published

2026-01-26

·

Updated

2026-06-22

·

CVE-2026-21509

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office 2016 Microsoft Office 2019 Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft 365 Apps
Description An issue in Microsoft Office arises from the reliance on untrusted inputs when making security decisions, which allows an unauthorized attacker to bypass security features locally. Specifically, the flaw enables the bypass of Object Linking and Embedding (OLE) security mechanisms. When a user opens a specially crafted document (such as RTF or DOC files), the exploit can automatically execute arbitrary code without user interaction, often leveraging the WebDAV protocol to retrieve additional payloads.
Real-world exploitation has been observed in several campaigns:
  • APT28 (Fancy Bear) weaponized this issue to target military, government, maritime, and transportation entities in Europe and Ukraine, deploying payloads like the "NotDoor" Outlook VBA backdoor and "BeardShell" implant.
  • Operation Neusploit utilized the flaw to deliver the "MiniDoor" email stealer and "PixyNetLoader" malware, the latter of which uses steganography to hide shellcode within PNG images.
  • BO Team (Black Owl) targeted Russian companies using RTF files to gain unauthorized access via Component Object Model (COM) compromise.
  • Forest Werewolf has also been observed exploiting this issue.
Technical details include the use of the Shell.Explorer.1 OLE component with CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} to facilitate the attack.
Recommendations For Microsoft Office 2016, install security update KB5002713. For Microsoft Office 2019, update to Build 10417.20095. For Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024, install the February 2026 security update. As a temporary mitigation for all affected versions, block the vulnerable OLE component by creating a registry DWORD value named Compatibility Flags set to 400 under the subkey {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} within the COM Compatibility node of the appropriate Microsoft Office registry path.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00828
CVE-2026-21509

Affected Products

Office