Junglewise Threat Intelligence

CVE-2026-64906: Microsoft Office Access heap-based buffer overflow

CVE-2026-64906 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a database management application widely used in enterprise environments for creating and managing databases. A heap-based buffer overflow vulnerability allows a local attacker with limited privileges to execute arbitrary code with the same access level as the user running Access, potentially compromising sensitive business data and enabling lateral movement within the network.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office Access due to improper input validation when processing certain database objects or file formats. The vulnerability requires local access to the affected system and typically requires a user to open a specially crafted Access file (.accdb or similar format) to trigger the overflow. Successful exploitation allows an attacker to overwrite heap memory and execute arbitrary code in the context of the Access process. A patch is available from Microsoft; users should apply security updates from the Microsoft Security Update Guide.

Affected products

  • Microsoft Office Access <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats