Impact
A heap-based buffer overflow has been identified in Microsoft Office, where an attacker can supply malicious content over a network to the application. The flaw, classified as CWE-122, allows arbitrary code to be executed within the Office process. If successfully exploited, an attacker can run any code with the privileges of the Office user, potentially resulting in full system compromise, data exfiltration, or persistence mechanisms being installed.
Affected Systems
The vulnerability affects all editions of Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. All publicly released versions of these products are impacted unless an update that addresses CVE‑2026‑77898 has been applied.
Risk and Exploitability
The base CVSS score of 7.5 indicates a high risk of exploitation. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at this time. The likely attack vector is via a remote network channel, where an attacker delivers a crafted Office document or initiates a malicious connection that triggers the buffer overflow. Successful exploitation requires the target to load the vulnerable Office application with the malicious input, which is typically achievable through phishing or remote collaboration mechanisms.
OpenCVE Enrichment