Executive brief
Microsoft Office Access is a database management application used to create and manage business databases. A stack-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Access, potentially leading to complete system compromise or data theft.
Technical details
A stack-based buffer overflow vulnerability exists in Microsoft Office Access due to insufficient bounds checking when processing certain input. An attacker with local access can exploit this flaw by crafting a malicious Access database file or input that triggers the overflow, allowing arbitrary code execution in the context of the user running the application. The vulnerability requires local file access and does not appear to have been exploited in the wild at the time of publication.
Affected products
- Microsoft Office Access
Timeline
- 2026-08-11: disclosed