Executive brief
A security vulnerability exists in Microsoft Office and SharePoint that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. If successful, the attacker could gain the same permissions as the local user, potentially leading to data theft or full system compromise.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple Microsoft Office products and SharePoint Server. The vulnerability is triggered when the application fails to properly validate input while processing a crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious document, resulting in arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected versions of Office 2016, 2019, LTSC, and Microsoft 365.
Affected products
- Microsoft Office 2016 < 16.0.5561.1000
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft 365 Apps for Enterprise All versions
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory