Junglewise Threat Intelligence

CVE-2026-64903: Microsoft Office integer overflow in local execution

CVE-2026-64903 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used suite of productivity applications deployed across most organizations. An integer overflow vulnerability in the software could allow a local attacker to execute malicious code on affected systems, potentially compromising sensitive business documents and data stored within Office files.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft Office that can be exploited through specially crafted Office documents. The vulnerability requires local access to the affected system and can lead to arbitrary code execution with the privileges of the user running Office. The attack does not require network access or user interaction beyond opening a malicious document. Microsoft has released a security update to patch this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats