Description
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Published: 2026-07-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Heap-based buffer overflow in Microsoft Account permits an attacker who can reach the service over a network to execute arbitrary code with the privileges of the account service.

Affected Systems

The vulnerability impacts the Microsoft Account product, but no specific affected versions are disclosed by the CNA. Administrators should verify the patch status of all Microsoft Account deployments regardless of the environment, as the data does not delineate which releases are affected.

Risk and Exploitability

The CVSS score of 9.8 flags critical severity, while the EPSS score of less than 1 % indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, remote code execution could compromise system integrity and availability if an attacker succeeds. The attack vector is inferred to be remote, network‑based communication toward the Microsoft Account service, based on the description that the overflow is exploitable over a network.

Generated by OpenCVE AI on August 3, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Account update for CVE‑2026‑56165 available through the Microsoft Security Response Center (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165).
  • If a patch is not yet available, restrict inbound network traffic to the Microsoft Account service using firewall or network segmentation to prevent unauthorized access to the vulnerable endpoint.
  • Monitor authentication logs and system events for signs of attempted exploitation, such as abnormal traffic patterns or error messages related to buffer handling.

Generated by OpenCVE AI on August 3, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft account
Vendors & Products Microsoft account

Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Title Microsoft Account Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft microsoft Account
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:microsoft_account:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Account
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Account Microsoft Account
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:15:08.502Z

Reserved: 2026-06-19T13:53:31.989Z

Link: CVE-2026-56165

cve-icon Vulnrichment

Updated: 2026-07-24T14:49:34.013Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:34.750

Modified: 2026-07-30T15:46:42.520

Link: CVE-2026-56165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow