Junglewise Threat Intelligence

CVE-2026-64909: Microsoft Office integer underflow allows local code execution

CVE-2026-64909 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains an integer underflow vulnerability that allows a local attacker to execute arbitrary code on a user's computer. An attacker with access to the system could exploit this flaw by crafting a malicious document, potentially leading to complete compromise of the affected machine and unauthorized access to sensitive business data.

Technical details

The vulnerability is an integer underflow (wrap or wraparound) condition in Microsoft Office. It requires local attack vector, meaning an attacker must have access to the affected system or convince a user to open a malicious Office document. The flaw allows an unauthenticated attacker to achieve local code execution with user-level privileges. Successful exploitation could result in arbitrary code execution in the context of the user running Microsoft Office. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats