Junglewise Threat Intelligence

CVE-2026-55125: Microsoft Office heap overflow in code execution

CVE-2026-55125 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Office and SharePoint that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. If successful, the attacker could gain the same permissions as the local user, potentially leading to data theft or full system compromise.

Technical details

A heap-based buffer overflow (CWE-122) exists in multiple Microsoft Office products and SharePoint Server. The vulnerability is triggered when the application fails to properly validate input while processing a crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious document, resulting in arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected versions of Office 2016, 2019, LTSC, and Microsoft 365.

Affected products

  • Microsoft Office 2016 < 16.0.5561.1000
  • Microsoft Office 2019 All versions
  • Microsoft Office LTSC 2021 All versions
  • Microsoft Office LTSC 2024 All versions
  • Microsoft 365 Apps for Enterprise All versions
  • Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats