Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in certain Microsoft Office applications. An attacker can execute arbitrary code locally. Such code execution would give the attacker full control of the compromised system, allowing further lateral movement or persistence.

Affected Systems

The flaw affects a range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021 and Office LTSC 2024. No specific version numbers were listed, so all releases of these products are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is opening a specially crafted Office document, after a user is convinced to do so through social engineering or phishing, which can trigger the heap-based buffer overflow and grant the attacker local code execution with the victim's privileges. While exploitation is local, it can lead to full system compromise, enabling persistence or lateral movement.

Generated by OpenCVE AI on July 31, 2026 at 07:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for the affected Office versions as detailed on the Microsoft Security Response Center update guide.
  • As a temporary measure, configure Office to disable automatic macro execution and enforce the highest macro security level to reduce the risk of malicious code delivery.
  • Block or tightly monitor the execution of Office binaries from untrusted network locations to prevent attackers from executing malicious Office files on the local machine.

Generated by OpenCVE AI on July 31, 2026 at 07:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:51.039Z

Reserved: 2026-06-16T14:12:44.284Z

Link: CVE-2026-55017

cve-icon Vulnrichment

Updated: 2026-07-14T19:06:04.577Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow