Description
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw (CWE‑190) in Microsoft Office Word is also a buffer overflow (CWE‑122). The bug can be triggered by processing a specially crafted document, allowing an attacker with access to the file to execute arbitrary code locally using the privileges of the current user. This flaw exposes confidentiality, integrity, and availability risks and can serve as a foothold for lateral movement if privilege escalation follows.

Affected Systems

This vulnerability affects several Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 2016, Office for Mac 2021, Office for Mac 2024, Word 2016, and SharePoint Server versions 2016, 2019, and Subscription Edition. Exact affected product versions are not enumerated in the data; however every recent release of the listed products is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw, and the EPSS score is <1%, indicating a low probability of exploitation. The vulnerability is not in CISA KEV. Based on the description, the most plausible attack vector is local file processing – an attacker who can supply a malicious document to a user or a system service will trigger the overflow. Thus an unauthenticated or authenticated local user can exploit the flaw. No elevated trust or network interaction is necessary. While the flaw is not yet seen in widespread exploitation, its high severity and local nature still warrant prompt remediation.

Generated by OpenCVE AI on July 31, 2026 at 06:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office update that contains the patch for CVE-2026-55033, making sure all Office components are refreshed to the newest release.
  • Configure Office software to block or quarantine documents that contain suspicious macros or loaders, and use the default \"Do Not Open\" security settings for unknown documents.
  • Limit the ability of ordinary users to open documents from untrusted network locations, and enforce strict content inspection policies for files entering the organization.

Generated by OpenCVE AI on July 31, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Title Microsoft Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
Weaknesses CWE-122
CWE-190
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:57:06.084Z

Reserved: 2026-06-16T14:13:49.835Z

Link: CVE-2026-55033

cve-icon Vulnrichment

Updated: 2026-07-14T19:11:48.156Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:00:08Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound