Junglewise Threat Intelligence

CVE-2026-55045: Microsoft Office out-of-bounds read code execution

CVE-2026-55045 · Severity: high · CVSS 8.4 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office and SharePoint Server could allow an attacker to execute malicious code on a user's computer. Microsoft Office is a widely used suite of productivity tools, and SharePoint is a platform for document management and collaboration. If exploited, this flaw could allow an unauthorized person to gain control over a system, potentially leading to data theft or further network compromise.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application improperly handles memory during the processing of specific data, allowing an attacker to read beyond the intended buffer. This memory corruption can be leveraged to achieve local code execution. The attack vector is local, meaning an attacker would typically need to convince a user to open a specially crafted file or have existing access to the system. Affected products include Office 2016, 2019, LTSC versions, and SharePoint Server 2016/2019. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-07-14: advisory: Microsoft released security update guide.

References

Related threats