
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20943 is an untrusted search path vulnerability (CWE-426) in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2016 (x86 and x64), Office Deployment Tool (versions before 16.0.19426.20170), SharePoint Server 2016 Enterprise, SharePoint Server 2019, and SharePoint Server Subscription Edition (versions before 16.0.19127.20442). It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning Microsoft Office searches for and loads libraries or executables from directories that an attacker can influence — a technique mapped to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). An attacker can place a malicious DLL or executable in a directory that Office searches before the legitimate path, causing it to be loaded and executed when a user opens an Office application or file. Exploitation requires local access to the target system and user interaction (e.g., opening a malicious file or triggering an Office operation), making the attack complexity high (Microsoft MSRC, Feedly).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Microsoft Office, potentially leading to complete system compromise. This includes unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files or data (high integrity impact), and disruption of service availability. The attack is constrained to the local system and does not change scope, but could serve as a stepping stone for privilege escalation or lateral movement if the compromised user account has elevated permissions (Microsoft MSRC, Feedly).
winword.exe, excel.exe, powerpnt.exe) such as cmd.exe, powershell.exe, or network utilities; Office processes loading DLLs from non-standard or user-writable paths.Microsoft released security updates on January 13, 2026, addressing this vulnerability. Affected products should be updated to: Office Deployment Tool version 16.0.19426.20170 or later, SharePoint Server Subscription Edition version 16.0.19127.20442 or later, Microsoft Office 2016 version 16.0.5535.1000 or later, and SharePoint Server 2019 version 16.0.10417.20083 or later. As interim mitigations, organizations should implement application whitelisting (e.g., Windows Defender Application Control or AppLocker) to restrict unsigned DLL loading, enforce the principle of least privilege to limit the impact of successful exploitation, and educate users about the risks of opening files from untrusted sources (Microsoft MSRC, Feedly).
CVE-2026-20943 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Coverage from outlets such as BleepingComputer, Cybersecurity News, and GBHackers noted the patch release but did not single out this CVE as particularly high-risk given its local-only attack vector and lack of active exploitation (BleepingComputer, Cybersecurity News). The Zero Day Initiative's January 2026 security update review also covered the patch cycle broadly (ZDI). Sophos and SANS ISC similarly included it in their Patch Tuesday roundups without flagging it as a priority concern (Sophos, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."