Junglewise Threat Intelligence

CVE-2026-64908: Microsoft Office Access heap buffer overflow

CVE-2026-64908 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a database management application used to create and manage business data. A heap buffer overflow vulnerability in Access could allow an attacker with local access to execute arbitrary code with the privileges of the user running the application, potentially leading to data theft, system compromise, or lateral movement within an organization.

Technical details

A heap-based buffer overflow exists in Microsoft Office Access, likely in a file parsing or data processing component. The vulnerability is triggered when Access processes a specially crafted input that causes a buffer overflow on the heap, allowing an attacker to overwrite adjacent memory structures. This enables arbitrary code execution with the privileges of the user running the Access application. The attack vector is local; an attacker would need to either trick a user into opening a malicious file or have direct access to the system. No patch information is currently available in the advisory.

Affected products

  • Microsoft Office Access

Timeline

  • 2026-08-11: disclosed
  • other: Not yet reported as exploited in the wild

References

Related threats