Description
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a heap‑based buffer overflow (CWE‑122, CWE‑787) in Microsoft Office Word. An attacker can embed malicious content in a Word document or SharePoint file such that when the victim opens it, the overflow occurs, allowing arbitrary code to execute with the privileges of the user who launched Word.

Affected Systems

Affected products include Microsoft Word 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, the Office LTSC 2021 and LTSC 2024 editions, and all Microsoft SharePoint Server 2016, 2019 and Subscription Edition deployments. Version details are not supplied in the advisory, so administrators should verify that their installations are at least on the latest cumulative update for the respective product line.

Risk and Exploitability

The CVSS score of 7.8 denotes a high severity for this vulnerability. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious Word document could be delivered via SharePoint or other file distribution methods, but the advisory does not explicitly state SharePoint as an attack vector. The attack requires a victim to open the malicious document locally or through SharePoint; it cannot be triggered remotely over the network.

Generated by OpenCVE AI on August 13, 2026 at 12:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Office update that addresses CVE‑2026‑55130, which can be downloaded from the Microsoft Security Response Center update guide.
  • If the update cannot be applied immediately, reduce exposure by configuring Windows to block opening of untrusted documents from external sources and by disabling macro execution in Word.
  • Continuously monitor for signs of exploitation, such as Windows Event Log entries indicating the execution of unexpected processes or Word crashes, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 13, 2026 at 12:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Title Microsoft Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:05:20.875Z

Reserved: 2026-06-16T15:03:49.681Z

Link: CVE-2026-55130

cve-icon Vulnrichment

Updated: 2026-07-14T19:06:06.418Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-14T18:18:19.587

Modified: 2026-07-15T20:12:41.697

Link: CVE-2026-55130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:45:03Z

Weaknesses