Junglewise Threat Intelligence

CVE-2026-45463: Microsoft Office heap-based buffer overflow

CVE-2026-45463 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office could allow an unauthorized person to run malicious code on a computer where the software is installed. This type of flaw typically allows an attacker to gain full control over the affected system, potentially leading to the theft of sensitive data or the disruption of business operations. Because the attack occurs locally, it often requires the attacker to already have some form of access to the machine or for a user to be tricked into running a malicious file.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office, stemming from an underlying integer underflow (CWE-191) and stack-based buffer overflow (CWE-121) conditions. An attacker can exploit this flaw to execute arbitrary code with the privileges of the current user. The attack vector is classified as local, meaning the attacker must have a presence on the target machine or leverage a delivery mechanism that executes the payload locally. According to the CVSS 3.1 vector, no elevated privileges or user interaction are required for successful exploitation. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office

Timeline

  • 2026-06-09: disclosed: CVE published by Microsoft and NVD

References

Related threats