Junglewise Threat Intelligence

CVE-2026-55049: Microsoft Office heap buffer overflow code execution

CVE-2026-55049 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A security vulnerability has been identified that could allow an attacker to execute malicious code on a user's computer if the user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the user's data and the ability for an attacker to perform unauthorized actions on the affected system.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in multiple versions of Microsoft Office across Windows and macOS platforms. The flaw is triggered when the application improperly handles memory allocation while processing a maliciously crafted file. An attacker can exploit this by convincing a user to open a specially crafted document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), but does not require prior administrative privileges. Microsoft has released security updates to address this issue across affected Office 2016, 2019, 2021, 2024, and 365 versions.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats