Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-69442 is a heap‑based buffer overflow (CWE‑122) that lets an unauthorized attacker execute arbitrary code on a vulnerable Microsoft Office installation via the network. The flaw can compromise confidentiality, integrity, and availability by allowing a malicious actor to run code with the same privileges as the user opening the document. The impact is system‑wide unless the user is running under a highly restricted account.

Affected Systems

Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024 are affected. No specific vulnerable revision numbers are supplied in the CNA data, so all current builds of these products are potentially at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability with the likely attack vector inferred to be a malicious Office document sent over a network. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that while the flaw is severe, documented widespread exploitation has not yet been reported. The vulnerability requires that the target system has a vulnerable Office installation and accepts networked Office files; thus, remote hosts can trick the victim into opening a specially crafted document to trigger the overflow and achieve code execution.

Generated by OpenCVE AI on September 8, 2026 at 21:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office update via Windows Update or the Office update channel to patch the heap‑based overflow.
  • If a patch cannot be applied immediately, isolate or block the vulnerable endpoints from inbound network traffic that could deliver malicious Office files.
  • Enforce stricter application settings such as disabling macros and restricting unsigned Office document execution to reduce the risk of exploitation.

Generated by OpenCVE AI on September 8, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2016 Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:35.343Z

Reserved: 2026-08-03T20:59:32.784Z

Link: CVE-2026-69442

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:08.413

Modified: 2026-09-08T19:23:00.357

Link: CVE-2026-69442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow