Junglewise Threat Intelligence

CVE-2026-64898: Microsoft Office heap-based buffer overflow

CVE-2026-64898 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely used productivity suite for document creation and editing. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code with the privileges of the user running Office, potentially leading to data theft, system compromise, or malware installation.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office, triggered when processing specially crafted input. The vulnerability allows an attacker to overflow a heap buffer, enabling arbitrary code execution in the context of the affected Office process. Local execution is required; this is not a remote code execution vulnerability. An attacker must craft a malicious document or input that, when processed by Office, triggers the overflow. Microsoft has released or is preparing patches to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats