Description
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow in Microsoft Office Access that enables an attacker to run arbitrary code when a vulnerable Access file is opened. The flaw can be triggered by a specially crafted Access file and may allow the attacker to hijack control flow, potentially leading to information disclosure or denial of service if the injected code exploits further system components. The weakness is identified as CWE‑121, a classic stack exploit.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (both 32‑bit and other editions), Microsoft Office 2019, Office LTSC 2021, and Office LTSC 2024. The update guide references all these versions; specific sub‑versions are not explicitly listed in the data, so any installation of the listed products is considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. EPSS is not available, and the exploit is not listed in CISA’s KEV catalog, implying no known widespread or controlled exploitation as of the data. The likely attack vector is through a malicious Access file opened by a user or via a remote network location. An attacker with local access or one able to deliver a malicious file to a vulnerable client can trigger the overflow and execute code, potentially compromising the local machine.

Generated by OpenCVE AI on August 12, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Patch for CVE‑2026‑64912 via the official update channel.
  • Ensure all impacted Office applications are updated to the latest cumulative security release.
  • If a patch is not yet available, restrict the opening of unknown Access files, enforce application whitelisting, and use antivirus software to scan for malicious content.

Generated by OpenCVE AI on August 12, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft access
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
Vendors & Products Microsoft access

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Title Microsoft Access Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-121
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:access_2016:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Access Access 2016 Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:26.854Z

Reserved: 2026-07-20T20:25:40.976Z

Link: CVE-2026-64912

cve-icon Vulnrichment

Updated: 2026-08-11T18:57:08.064Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:52.440

Modified: 2026-08-14T15:12:04.093

Link: CVE-2026-64912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:45:02Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow