Junglewise Threat Intelligence

CVE-2026-64910: Microsoft Office untrusted pointer dereference

CVE-2026-64910 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains a vulnerability where untrusted data can cause a pointer dereference, allowing an attacker to execute arbitrary code on a user's computer. This could lead to complete compromise of the affected system, theft of sensitive documents, or lateral movement within an organization.

Technical details

The vulnerability is a classic untrusted pointer dereference in Microsoft Office, a memory corruption flaw where the application fails to validate a pointer before dereferencing it. An attacker can exploit this via a specially crafted Office document or file. The attack requires local code execution context but does not require elevated privileges or user interaction beyond opening a malicious document. Successful exploitation results in arbitrary code execution with the privileges of the user running Office.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats