Junglewise Threat Intelligence

CVE-2026-55055: Microsoft Office Word stack-based buffer overflow

CVE-2026-55055 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office Word, Microsoft Word, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used word processing application for creating and editing documents. A security vulnerability has been identified that could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious document. This could lead to the theft of sensitive data, unauthorized software installation, or disruption of business operations.

Technical details

A stack-based buffer overflow (CWE-121) exists in Microsoft Office Word. The vulnerability is triggered when the application fails to properly validate input while parsing a document, allowing an attacker to overwrite memory on the stack. While the attack vector is classified as local, it typically requires user interaction (UI:R), such as opening a malicious Word document received via email or downloaded from the web. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office and SharePoint Server.

Affected products

  • Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, Office for Mac, SharePoint Server

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats