PT-2026-4775 · Microsoft · Office
Oruga00
+1
·
Published
2026-01-26
·
Updated
2026-06-22
·
CVE-2026-21509
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office LTSC 2021
Microsoft Office LTSC 2024
Microsoft 365 Apps
Description
An issue in Microsoft Office arises from the reliance on untrusted inputs when making security decisions, which allows an unauthorized attacker to bypass security features locally. Specifically, the flaw enables the bypass of Object Linking and Embedding (OLE) security mechanisms. When a user opens a specially crafted document (such as RTF or DOC files), the exploit can automatically execute arbitrary code without user interaction, often leveraging the WebDAV protocol to retrieve additional payloads.
Real-world exploitation has been observed in several campaigns:
- APT28 (Fancy Bear) weaponized this issue to target military, government, maritime, and transportation entities in Europe and Ukraine, deploying payloads like the "NotDoor" Outlook VBA backdoor and "BeardShell" implant.
- Operation Neusploit utilized the flaw to deliver the "MiniDoor" email stealer and "PixyNetLoader" malware, the latter of which uses steganography to hide shellcode within PNG images.
- BO Team (Black Owl) targeted Russian companies using RTF files to gain unauthorized access via Component Object Model (COM) compromise.
- Forest Werewolf has also been observed exploiting this issue.
Technical details include the use of the
Shell.Explorer.1 OLE component with CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} to facilitate the attack.Recommendations
For Microsoft Office 2016, install security update KB5002713.
For Microsoft Office 2019, update to Build 10417.20095.
For Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024, install the February 2026 security update.
As a temporary mitigation for all affected versions, block the vulnerable OLE component by creating a registry DWORD value named
Compatibility Flags set to 400 under the subkey {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} within the COM Compatibility node of the appropriate Microsoft Office registry path.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office