Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow has been identified in the Microsoft Office graphics component. An attacker who can supply crafted input while the Office application is running can trigger the overflow and execute arbitrary code locally on the target system. The vulnerability is a classic CWE‑122 flaw that allows local adversaries to compromise confidentiality, integrity, and availability of the affected Office instance.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021 LTSC, Microsoft Office 2024 LTSC, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version details are not published, so all releases under those product families are treated as at risk until the next patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity and the EPSS score is currently not available, suggesting that no public exploit has been observed to date. The vulnerability is not listed in the CISA KEV catalog, implying that it may not yet be actively weaponized. Nonetheless, the local nature of the attack suggests that privileged or authenticated users, or anyone capable of creating a malicious Office document, can exploit this flaw. The attack vector is inferred to be local, triggered by processing crafted inputs within the Office graphics subsystem.

Generated by OpenCVE AI on August 12, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Office security updates released by Microsoft, following the guidance available at the Microsoft Security Response Center for CVE‑2026‑65664.
  • Verify that Automatic Updates are enabled for the Office suite to ensure future patches are installed without manual intervention.
  • If a patch is not immediately available, restrict user access to untrusted or external Office documents and consider disabling the vulnerable graphics component via group policy as a temporary mitigation.

Generated by OpenCVE AI on August 12, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2019
Microsoft microsoft Office 365 For Mac
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Graphics Component Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Microsoft 365 Apps For Enterprise Microsoft Office 2019 Microsoft Office 365 For Mac Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Microsoft Office Ltsc For Mac 2021 Microsoft Office Ltsc For Mac 2024 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:39.457Z

Reserved: 2026-07-22T18:16:01.897Z

Link: CVE-2026-65664

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:25.397Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:54.633

Modified: 2026-08-14T17:45:30.480

Link: CVE-2026-65664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:45:02Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow