Junglewise Threat Intelligence

CVE-2026-55130: Microsoft Office Word heap buffer overflow

CVE-2026-55130 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft 365 Apps for Enterprise, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Word 2016, Microsoft Office LTSC 2021, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Office Word could allow an attacker to execute malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted document. Successful exploitation could lead to a full compromise of the user's data and system access.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Office Word and related SharePoint server components. The vulnerability is triggered when the application fails to properly validate input while processing a document, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, resulting in arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected Office and SharePoint versions.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise >= 16.0.1
  • Microsoft Microsoft Office 2019 >= 19.0.0
  • Microsoft Microsoft Office LTSC 2021 >= 16.0.1
  • Microsoft Microsoft Office LTSC 2024 >= 16.0.0
  • Microsoft Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
  • Microsoft Microsoft SharePoint Server 2019 < 16.0.10417.20175
  • Microsoft Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
  • Microsoft Microsoft Word 2016 < 16.0.5561.1000

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-55130 by Microsoft.

References

Related threats