Impact
CVE-2026-69442 is a heap‑based buffer overflow (CWE‑122) that lets an unauthorized attacker execute arbitrary code on a vulnerable Microsoft Office installation via the network. The flaw can compromise confidentiality, integrity, and availability by allowing a malicious actor to run code with the same privileges as the user opening the document. The impact is system‑wide unless the user is running under a highly restricted account.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024 are affected. No specific vulnerable revision numbers are supplied in the CNA data, so all current builds of these products are potentially at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability with the likely attack vector inferred to be a malicious Office document sent over a network. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that while the flaw is severe, documented widespread exploitation has not yet been reported. The vulnerability requires that the target system has a vulnerable Office installation and accepts networked Office files; thus, remote hosts can trick the victim into opening a specially crafted document to trigger the overflow and achieve code execution.
OpenCVE Enrichment