Description
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a heap‑based buffer overflow (CWE‑122) in Microsoft Office Word. An attacker can embed malicious content in a Word document or SharePoint file such that when the victim opens it, the overflow occurs, allowing arbitrary code to execute with the privileges of the user who launched Word.

Affected Systems

Affected products include Microsoft Word 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, the Office LTSC 2021 and LTSC 2024 editions, and all Microsoft SharePoint Server 2016, 2019 and Subscription Edition deployments. Version details are not supplied in the advisory, so administrators should verify that their installations are at least on the latest cumulative update for the respective product line.

Risk and Exploitability

The CVSS score of 7.8 represents high severity, with a local privilege requirement and user interaction. The EPSS of less than 1% suggests a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious file could be delivered via SharePoint, but the advisory does not explicitly state SharePoint as an attack vector; the attack vector requires a user to open a malicious document locally or via SharePoint; it cannot be triggered remotely over the network.

Generated by OpenCVE AI on July 31, 2026 at 06:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Office update that addresses CVE‑2026‑55130, which can be downloaded from the Microsoft Security Response Center update guide.
  • If the update cannot be applied immediately, reduce exposure by configuring Windows to block opening of untrusted documents from external sources and by disabling macro execution in Word.
  • Continuously monitor for signs of exploitation, such as Windows Event Log entries indicating the execution of unexpected processes or Word crashes, and investigate any anomalies promptly.

Generated by OpenCVE AI on July 31, 2026 at 06:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Title Microsoft Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:38.896Z

Reserved: 2026-06-16T15:03:49.681Z

Link: CVE-2026-55130

cve-icon Vulnrichment

Updated: 2026-07-14T19:06:06.418Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow