
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20952 is a use-after-free vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2016, 2019, 2021, 2024 (Windows and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is a use-after-free condition (CWE-416) within Microsoft Office's memory management, where a freed memory region can be accessed and manipulated by an attacker. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). Notably, threat intelligence indicates the vulnerability is exploitable via the Outlook Preview Pane — meaning simply previewing a malicious email in Outlook can trigger the flaw without any additional user action, effectively lowering the practical attack barrier despite the local vector classification (Feedly, Microsoft MSRC).
Successful exploitation results in arbitrary code execution on the affected system with high impact to confidentiality, integrity, and availability. An attacker who exploits this vulnerability could gain full control of the targeted machine, enabling data exfiltration, installation of malware, lateral movement within enterprise networks, or further privilege escalation. The Outlook Preview Pane attack surface makes this particularly dangerous in enterprise environments where email preview is routinely enabled, as exploitation requires no deliberate file opening or macro execution by the victim (Feedly).
OUTLOOK.EXE, WINWORD.EXE) to unknown external IP addresses or domains shortly after email preview events.OUTLOOK.EXE or other Office applications (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) without user-initiated actions.%TEMP%, %APPDATA%, or Office-related directories by Office processes; new scheduled tasks or registry run keys created by Office process accounts.HKCU\Software\Microsoft\Windows\CurrentVersion\Run) created around the time of suspicious Office activity.Microsoft released patches for all affected products on January 13, 2026, as part of the January 2026 Patch Tuesday update cycle. Affected versions include Microsoft Office 2016 (update to build 16.0.5535.1000 or later), Office 2019, Office 2021, Office 2024, Office LTSC for Mac 2021/2024 (update to 16.105.26011018 or later), and Microsoft 365 Apps for Enterprise — all should be updated immediately via Windows Update or the Microsoft Update Catalog (Microsoft MSRC). As a temporary workaround until patching is complete, administrators should consider disabling the Outlook Preview Pane to eliminate the zero-interaction attack surface. Implementing email filtering to block suspicious or unexpected Office file attachments provides additional defense-in-depth (Feedly).
The January 2026 Patch Tuesday release, which addressed 113–114 CVEs including CVE-2026-20952, received broad coverage from security vendors and researchers. Tenable highlighted the patch batch as significant given the volume and severity of fixes, noting the Outlook Preview Pane attack vector as a particularly concerning aspect of Office vulnerabilities in this release (Tenable). Zero Day Initiative (ZDI), Qualys, CrowdStrike, Sophos, and Arctic Wolf all published Patch Tuesday analyses covering this vulnerability as part of the broader January 2026 update (ZDI, Qualys). Community sentiment on platforms like Mastodon (infosec.exchange) reflected concern about the zero-interaction exploitation potential via Outlook Preview Pane.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."