Junglewise Threat Intelligence

CVE-2026-40363: Microsoft Office heap buffer overflow

CVE-2026-40363 · Severity: high · CVSS 8.4 · Published 2026-05-12

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker who has gained access to a local system could exploit this flaw to run unauthorized code with elevated privileges. This could lead to a complete compromise of the affected computer, including the theft of sensitive documents and disruption of business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists within Microsoft Office. The vulnerability is triggered when the application improperly handles data in memory, allowing an attacker to overwrite adjacent memory locations. While the attack vector is classified as local, it requires no special privileges (PR:N) and no user interaction (UI:N). Successful exploitation allows for arbitrary code execution in the context of the logged-in user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats