Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer, potentially leading to data theft or full system compromise. To be successful, the attacker must convince a user to open a specially crafted file.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office across Windows and macOS platforms. The vulnerability is triggered when the application fails to properly validate input while processing a malicious file, leading to memory corruption. An attacker can exploit this by convincing a user to open a specially crafted document, resulting in arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue across affected versions including Office 2016, 2019, LTSC, and Microsoft 365 Apps.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide