Executive brief
A critical vulnerability has been identified in the Microsoft Account service, which manages user authentication and identity across Microsoft platforms. An unauthorized attacker could exploit this flaw over the internet to execute malicious code on the system. This could lead to a complete compromise of the service, including unauthorized access to user data and disruption of authentication operations.
Technical details
This vulnerability is classified as a heap-based buffer overflow (CWE-122) within the Microsoft Account service. The flaw allows an unauthenticated remote attacker to send specially crafted data over the network to trigger memory corruption. Successful exploitation enables arbitrary code execution with the privileges of the service. The attack requires no user interaction and has a low complexity, resulting in a critical impact on confidentiality, integrity, and availability. Microsoft has categorized this as an exclusively hosted service vulnerability, implying the fix is managed on the service provider side.
Affected products
- Microsoft Microsoft Account All versions
Timeline
- 2026-07-24: disclosed: Initial publication of the CVE record.
- 2026-07-24: advisory: Microsoft Security Response Center advisory published.