Description
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in Microsoft Office’s graphics component. An attacker who can provide a crafted file to the affected Office application can trigger the overflow and execute arbitrary code on the local machine. This flaw falls under CWE‑121 and CWE‑79 and can compromise the confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected systems include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and the Mac equivalents of the LTSC releases. No specific version details are supplied in the advisory, so any installation of these products issued before the MSRC patch is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.8 marks the flaw as high severity. The EPSS score is reported as < 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV collection. The attack vector appears to be local; an attacker needs to provide a malicious Office document or image that triggers the graphics component processing.

Generated by OpenCVE AI on August 15, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update for Microsoft Office detailed in the MSRC advisory for CVE-2026-66807.
  • Update all Microsoft 365 Apps, Office 2019, Office 365 for Mac, LTSC 2021, LTSC 2024, and Mac LTSC versions to the latest patch level.
  • If immediate patching is not possible, enforce antivirus and device isolation, limit execution of unknown Office files, and enable system integrity monitoring.

Generated by OpenCVE AI on August 15, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
References
Metrics threat_severity

None

threat_severity

Low


Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Graphics Component Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-121
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:48.706Z

Reserved: 2026-07-27T19:02:26.601Z

Link: CVE-2026-66807

cve-icon Vulnrichment

Updated: 2026-08-11T18:11:39.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:02.107

Modified: 2026-08-14T17:00:55.423

Link: CVE-2026-66807

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-14T17:00:00Z

Links: CVE-2026-66807 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T01:30:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')