Executive brief
Microsoft Office, a widely used suite of productivity applications, is affected by a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. Successful exploitation could lead to unauthorized access to sensitive data, installation of malicious software, or disruption of business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps. The vulnerability is triggered when the application fails to properly validate input, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, resulting in arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide.