Description
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute arbitrary code locally. The flaw occurs when Office processes a specially crafted document, causing an overflow that leads to code execution with the privileges of the current user. This weakness, a CWE-122 condition, could let an attacker run arbitrary programs, modify or delete data, or establish privileged accounts on the affected system. The vulnerability requires that the user open a malicious Office file, making it exploitable through social engineering or malicious attachments.

Affected Systems

Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version information is not specified in the advisory, so any installation of these products could be vulnerable.

Risk and Exploitability

The CVSS score is 8.4, which is high and indicates a serious threat. The EPSS score remains low (<1%), suggesting that exploitation probability is presently low. The vulnerability is not listed in CISA KEV. An attacker must first persuade a user to open a malicious Office document; once the document is processed, Office will execute code with the current user’s privileges. The impact can be full user‑level control, including installing software, tampering with data, and creating privileged accounts. While the local nature of execution limits abuse to the current user, the seriousness of the effect means patching remains critical.

Generated by OpenCVE AI on September 26, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Office update from Microsoft that patches the heap overflow flaw (see the Microsoft Security Response Center link for the specific update).
  • Restrict the opening of Office documents from untrusted sources by disabling automated macro execution and enabling the Office Document Isolation feature.
  • Apply network segmentation and firewall rules to limit exposure of Office clients to potentially malicious file delivery channels such as untrusted email attachments or shared network folders.

Generated by OpenCVE AI on September 26, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document. The updates address the vulnerability by correcting how Office validates input before loading DLL files. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Title Microsoft Office Remote Code Execution Vulnerability Microsoft Outlook and Word Remote Code Execution Vulnerability
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Thu, 24 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document. The updates address the vulnerability by correcting how Office validates input before loading DLL files.
Title Microsoft Outlook and Word Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Title Microsoft Word Remote Code Execution Vulnerability Microsoft Outlook and Word Remote Code Execution Vulnerability

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Title Microsoft Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-29T20:24:12.612Z

Reserved: 2026-08-24T17:28:00.622Z

Link: CVE-2026-78510

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:27.392Z

cve-icon NVD

Status : Modified

Published: 2026-09-08T18:20:46.200

Modified: 2026-09-25T22:18:36.710

Link: CVE-2026-78510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow