Junglewise Threat Intelligence

CVE-2026-55133: Microsoft Office OneNote heap overflow code execution

CVE-2026-55133 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise. Vendors: Microsoft.

Executive brief

Microsoft OneNote, a popular digital note-taking application, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. If successful, the attacker could run malicious software, access sensitive data, or disrupt business operations on the affected device.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Office OneNote. The vulnerability is triggered when the application improperly handles memory allocation while processing a malicious file. An attacker can exploit this by convincing a user to open a specially crafted document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), but does not require prior administrative privileges (PR:N). Microsoft has released security updates to address this issue across affected versions of Office 365 and LTSC for both Windows and Mac.

Affected products

  • Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security release
  • Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats