CVE-2026-20943
vulnerability analysis and mitigation

Overview

CVE-2026-20943 is an untrusted search path vulnerability (CWE-426) in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2016 (x86 and x64), Office Deployment Tool (versions before 16.0.19426.20170), SharePoint Server 2016 Enterprise, SharePoint Server 2019, and SharePoint Server Subscription Edition (versions before 16.0.19127.20442). It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning Microsoft Office searches for and loads libraries or executables from directories that an attacker can influence — a technique mapped to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). An attacker can place a malicious DLL or executable in a directory that Office searches before the legitimate path, causing it to be loaded and executed when a user opens an Office application or file. Exploitation requires local access to the target system and user interaction (e.g., opening a malicious file or triggering an Office operation), making the attack complexity high (Microsoft MSRC, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Microsoft Office, potentially leading to complete system compromise. This includes unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files or data (high integrity impact), and disruption of service availability. The attack is constrained to the local system and does not change scope, but could serve as a stepping stone for privilege escalation or lateral movement if the compromised user account has elevated permissions (Microsoft MSRC, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target system running a vulnerable version of Microsoft Office 2016, Office Deployment Tool (before 16.0.19426.20170), or SharePoint Server (2016, 2019, or Subscription Edition before 16.0.19127.20442) with local access available.
  2. Identify writable search path directory: Determine a directory that Microsoft Office searches for libraries or executables before the legitimate system path — this could be a user-writable directory in the PATH environment variable or a directory local to the Office installation.
  3. Plant malicious binary: Place a crafted malicious DLL or executable with the name of a legitimate library expected by Office into the identified writable directory (DLL planting/hijacking technique).
  4. Trigger user interaction: Convince the target user to open a malicious Office file or perform an Office operation (e.g., opening a document, launching an Office application) that causes the application to search for and load the planted library.
  5. Achieve code execution: The Office application loads the attacker-controlled binary instead of the legitimate one, executing arbitrary code with the privileges of the logged-in user (Microsoft MSRC, Feedly).

Indicators of compromise

  • File System: Unexpected DLL or executable files placed in user-writable directories that appear in the system PATH or Office application directories; files with names matching legitimate Office or Windows libraries but with anomalous hashes or signatures.
  • Process: Unusual child processes spawned by Office applications (e.g., winword.exe, excel.exe, powerpnt.exe) such as cmd.exe, powershell.exe, or network utilities; Office processes loading DLLs from non-standard or user-writable paths.
  • Logs: Windows Event Logs (Event ID 7 - Image Load) showing Office processes loading modules from unexpected directories; AppLocker or Windows Defender Application Control logs flagging unsigned or untrusted DLL loads from Office processes.
  • Network: Unexpected outbound network connections originating from Office application processes to external IP addresses, which may indicate post-exploitation activity such as reverse shell or data exfiltration.

Mitigation and workarounds

Microsoft released security updates on January 13, 2026, addressing this vulnerability. Affected products should be updated to: Office Deployment Tool version 16.0.19426.20170 or later, SharePoint Server Subscription Edition version 16.0.19127.20442 or later, Microsoft Office 2016 version 16.0.5535.1000 or later, and SharePoint Server 2019 version 16.0.10417.20083 or later. As interim mitigations, organizations should implement application whitelisting (e.g., Windows Defender Application Control or AppLocker) to restrict unsigned DLL loading, enforce the principle of least privilege to limit the impact of successful exploitation, and educate users about the risks of opening files from untrusted sources (Microsoft MSRC, Feedly).

Community reactions

CVE-2026-20943 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Coverage from outlets such as BleepingComputer, Cybersecurity News, and GBHackers noted the patch release but did not single out this CVE as particularly high-risk given its local-only attack vector and lack of active exploitation (BleepingComputer, Cybersecurity News). The Zero Day Initiative's January 2026 security update review also covered the patch cycle broadly (ZDI). Sophos and SANS ISC similarly included it in their Patch Tuesday roundups without flagging it as a priority concern (Sophos, SANS ISC).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management