Description
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds write in Microsoft Office allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability can compromise confidentiality, integrity, and availability of affected systems if exploited, enabling an attacker to run malicious code with the privileges of the Office process.

Affected Systems

The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 (including Mac editions). Specific version numbers are not listed, so all current builds of these products are potentially impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network, where an attacker can deliver a crafted Office document or data stream that triggers the out‑of‑bounds write. Escalation to system privileges may occur if the Office process runs with elevated rights.

Generated by OpenCVE AI on September 9, 2026 at 02:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected Microsoft Office installations to the latest patch that addresses CVE‑2026‑78524 via Windows Update or the Office installer.
  • If an immediate update is not possible, block the transmission of Office files or mixed‑content data from untrusted external sources through network segmentation and firewall rules until the patch can be applied.
  • Configure Office to operate in a protected or safe mode that disables macros and enforces strict certificate validation, ensuring that only trusted documents are processed.

Generated by OpenCVE AI on September 9, 2026 at 02:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:*
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-787
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:26.424Z

Reserved: 2026-08-24T17:28:00.623Z

Link: CVE-2026-78524

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:08.720Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:48.100

Modified: 2026-09-17T20:18:33.140

Link: CVE-2026-78524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses