Executive brief
Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A security vulnerability has been identified that could allow an attacker to execute malicious code on a user's computer if the user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the user's data and the ability for an attacker to perform unauthorized actions on the affected system.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in multiple versions of Microsoft Office across Windows and macOS platforms. The flaw is triggered when the application improperly handles memory allocation while processing a maliciously crafted file. An attacker can exploit this by convincing a user to open a specially crafted document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), but does not require prior administrative privileges. Microsoft has released security updates to address this issue across affected Office 2016, 2019, 2021, 2024, and 365 versions.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide