Microsoft Office Vulnerability Allows Information Disclosure via HTML Injection
A ZDI-26-607 vulnerability in Microsoft Office permits remote attackers to disclose sensitive information through HTML injection, requiring user interaction.

The Zero Day Initiative (ZDI) has disclosed a significant vulnerability, designated ZDI-26-607, affecting Microsoft Office. This flaw permits remote attackers to gain unauthorized access to sensitive information residing on compromised installations. Exploitation of this vulnerability necessitates user interaction, typically involving the user visiting a malicious webpage or opening a specially crafted file.
The core of the vulnerability lies in how Microsoft Office handles query string parameters. Specifically, the software fails to adequately validate user-supplied data, creating an opening for attackers to inject arbitrary HTML code. This injection capability can then be leveraged by malicious actors to exfiltrate stored credentials, potentially leading to a broader compromise of user accounts and systems.
With a CVSS rating of 7.6, this vulnerability presents a considerable risk to users. The ability to disclose sensitive information, especially credentials, can pave the way for further attacks, including account takeover, unauthorized access to corporate networks, and data breaches. The requirement for user interaction, while a mitigating factor, does not eliminate the threat, as phishing campaigns and malicious document distribution remain common attack vectors.
Microsoft has addressed this vulnerability, with a fix available for the affected component, identified as home.office.com. The disclosure timeline indicates that the vulnerability was initially reported to the vendor on March 3, 2026, followed by a coordinated public release of the advisory on August 24, 2026. An update to the advisory was also published on the same date.
The vulnerability was reported by researcher kaijieguigui, who has been credited for their discovery. The ZDI advisory provides detailed technical information for security professionals and organizations to assess their exposure and implement necessary mitigations or apply the provided patches.
This disclosure underscores the persistent threat landscape surrounding widely used productivity software. Attackers continually seek weaknesses in applications like Microsoft Office to gain initial access or exfiltrate data. Organizations must remain vigilant, ensuring their software is up-to-date and that users are educated about the risks of interacting with untrusted content.
While the specific impact can vary depending on the user's environment and the type of sensitive information accessible, the potential for credential theft and subsequent system compromise makes ZDI-26-607 a notable vulnerability. Security teams should prioritize patching and review their security controls to prevent exploitation.