📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH now Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH now Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH now Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h
Vulnerabilities

CVE-2026-35436

High
CWE-1220 — Weakness Type
Published: May 12, 2026  ·  Modified: May 19, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

🤖 AI Executive Summary

CVE-2026-35436 is a privilege escalation vulnerability in Microsoft Office Click-To-Run with a CVSS score of 8.8, allowing authorized local attackers to elevate privileges through insufficient access control granularity. This vulnerability poses significant risk to Saudi organizations relying on Microsoft Office for critical operations. While no public exploit is currently available, the lack of a patch requires immediate compensating controls and monitoring.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 18, 2026 08:36
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi banking sector (SAMA-regulated institutions), government agencies (NCA oversight), healthcare organizations (MOH), and energy sector (ARAMCO, SABIC). The privilege escalation risk is particularly severe for organizations with multi-user workstations and shared Office environments. Telecom operators (STC, Mobily) and financial services firms face elevated risk due to widespread Office deployment. Government entities using Office for classified document handling require immediate attention.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare Energy and Utilities Telecommunications Defense and Security Education
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all Microsoft Office Click-To-Run installations across the organization
2. Restrict local administrative access and enforce principle of least privilege for all user accounts
3. Implement application whitelisting to control Office process execution
4. Enable Windows Defender Application Guard for Office applications in high-risk environments

Compensating Controls (until patch available):
5. Deploy endpoint detection and response (EDR) solutions to monitor Office process behavior and privilege escalation attempts
6. Implement file integrity monitoring on Office installation directories
7. Configure Windows Event Log auditing for privilege escalation events (Event ID 4688, 4689)
8. Restrict Office macro execution policies and disable VBA in untrusted documents
9. Enforce code integrity policies and disable kernel-mode driver installation

Detection Rules:
10. Monitor for unusual Office child processes spawning with elevated privileges
11. Alert on Office processes accessing LSASS or other sensitive system processes
12. Track modifications to Office Click-To-Run registry keys and installation paths
13. Monitor for Office processes attempting to write to System32 or Program Files directories
14. Subscribe to Microsoft security advisories for patch availability and apply immediately upon release
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع تثبيتات Microsoft Office Click-To-Run عبر المنظمة
2. تقييد الوصول الإداري المحلي وفرض مبدأ الحد الأدنى من الامتيازات لجميع حسابات المستخدمين
3. تطبيق قائمة التطبيقات المسموحة للتحكم في تنفيذ عمليات Office
4. تفعيل Windows Defender Application Guard لتطبيقات Office في البيئات عالية المخاطر

الضوابط التعويضية (حتى توفر التصحيح):
5. نشر حلول الكشف والاستجابة على نقاط النهاية (EDR) لمراقبة سلوك عمليات Office ومحاولات تصعيد الامتيازات
6. تطبيق مراقبة سلامة الملفات على مجلدات تثبيت Office
7. تكوين تدقيق سجل أحداث Windows لأحداث تصعيد الامتيازات (معرف الحدث 4688، 4689)
8. تقييد سياسات تنفيذ وحدات Office الماكرو وتعطيل VBA في المستندات غير الموثوقة
9. فرض سياسات سلامة الكود وتعطيل تثبيت برامج تشغيل وضع النواة

قواعد الكشف:
10. مراقبة عمليات Office الفرعية غير العادية التي تعمل بامتيازات مرتفعة
11. التنبيه على عمليات Office التي تحاول الوصول إلى LSASS أو عمليات النظام الحساسة الأخرى
12. تتبع التعديلات على مفاتيح تسجيل Office Click-To-Run ومسارات التثبيت
13. مراقبة عمليات Office التي تحاول الكتابة إلى مجلدات System32 أو Program Files
14. الاشتراك في تنبيهات أمان Microsoft وتطبيق التصحيحات فورًا عند توفرها
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Access Control Policy A.6.1.2 - User Registration and De-registration A.9.2.1 - User Access Management A.9.4.3 - Password Management A.12.4.1 - Event Logging A.12.4.3 - Administrator and Operator Logs
🔵 SAMA CSF
ID.AC-1 - Access Control Policy and Procedures ID.AC-2 - Physical and Logical Access Controls PR.AC-1 - Identities and Credentials Management PR.AC-4 - Access Rights Management DE.CM-1 - System Monitoring DE.AE-1 - Audit Logs
🟡 ISO 27001:2022
A.5.1.1 - Policies for information security A.6.1.2 - Information security roles and responsibilities A.8.1.1 - Screening A.9.1.1 - Access control policy A.9.2.1 - User registration and de-registration A.9.4.3 - Password management A.12.4.1 - Event logging
🟣 PCI DSS v4.0.1
Requirement 2.1 - Default security parameters Requirement 7 - Restrict access to data by business need to know Requirement 8 - Identify and authenticate access Requirement 10 - Track and monitor access to network resources
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-1220
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-05-12
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-1220
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.