Junglewise Threat Intelligence

CVE-2026-50301: Microsoft Office heap overflow code execution

CVE-2026-50301 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw by convincing a user to open a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or a complete disruption of the user's work environment.

Technical details

A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office, including Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps. The vulnerability is triggered when the application fails to properly validate input while processing a malicious file. An attacker can exploit this by enticing a user to open a specially crafted document, leading to arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue across affected versions.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to latest security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 up to latest security release
  • Microsoft Microsoft Office LTSC 2021 16.0.1 up to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 up to latest security release

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats