Description
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office Access contains a heap‑based buffer overflow that permits an attacker to run arbitrary code locally. The flaw originates when the program processes specially crafted data, allowing the attacker to overwrite critical memory structures and execute malicious instructions. The resulting compromise gives the attacker the same privileges as the user who opens the affected file, enabling the installation of malware, manipulation of data, or further lateral movements within the system.

Affected Systems

Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, and the long‑term servicing channel editions of Microsoft Office LTSC 2021 and LTSC 2024 are affected. The vulnerability applies to all builds tracked by Microsoft until an update is applied, as detailed in the Microsoft advisory referenced in the CVE record.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity for local attackers, while the EPSS score of < 1 % and absence from CISA KEV suggest that public exploitation is currently limited. The likely attack vector is opening a maliciously crafted file with Microsoft Access, a scenario that does not require network access or elevated privileges. Once a user opens such a file, the unchecked memory write can be leveraged to execute code at the user's privilege level. Given the potential impact on confidentiality, integrity, and availability, any environment that accepts untrusted Access files represents a high risk until a fix is applied.

Generated by OpenCVE AI on August 12, 2026 at 16:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update referenced in the advisory from msrc.microsoft.com
  • Block or remove the use of the vulnerable Access application in environments where it is not essential
  • Enforce strict file trust policies so that only users with explicit permission can open Microsoft Access files

Generated by OpenCVE AI on August 12, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft access
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
Vendors & Products Microsoft access

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Access 2016 (32-bit Edition)
Vendors & Products Microsoft microsoft Access 2016 (32-bit Edition)

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Title Microsoft Access Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:access_2016:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Access Access 2016 Microsoft Access 2016 (32-bit Edition) Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:25.280Z

Reserved: 2026-07-20T20:25:40.975Z

Link: CVE-2026-64906

cve-icon Vulnrichment

Updated: 2026-08-11T18:14:38.927Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:51.600

Modified: 2026-08-14T13:43:39.643

Link: CVE-2026-64906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow