Junglewise Threat Intelligence

CVE-2026-45461: Microsoft Office heap overflow code execution

CVE-2026-45461 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker with local access to a system could exploit this flaw to run unauthorized code, potentially leading to a full system takeover or theft of sensitive documents. This poses a significant risk to data confidentiality and the overall integrity of the affected workstation.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office, categorized as a Use After Free (CWE-416) by the vendor. The flaw can be triggered locally by an unauthorized attacker, requiring no special privileges or user interaction according to the CVSS vector. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user, potentially leading to a complete compromise of the host's confidentiality, integrity, and availability. Users are advised to consult the Microsoft Security Update Guide for relevant patches.

Affected products

  • Microsoft Office

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats