Junglewise Threat Intelligence

CVE-2026-55134: Microsoft Office Word stack-based buffer overflow

CVE-2026-55134 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

A security vulnerability has been identified in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw to execute malicious code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full system compromise, allowing the attacker to steal data, install programs, or disrupt business operations.

Technical details

A stack-based buffer overflow (CWE-121) exists in Microsoft Office Word. The vulnerability is triggered when the application fails to properly validate input while parsing a document, leading to memory corruption. An attacker can exploit this by convincing a user to open a specially crafted file (User Interaction required). Successful exploitation allows for arbitrary code execution in the context of the current user. The vulnerability affects multiple versions of Office, including Microsoft 365 Apps, Office LTSC, and SharePoint Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, Office for Mac, SharePoint Server

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via MSRC

References

Related threats