Executive brief
Microsoft Office Access is a database management application widely used by organizations to create and manage business data. A heap-based buffer overflow vulnerability in Access allows an attacker with local access to execute arbitrary code on the affected system, potentially compromising data integrity and system security.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office Access that allows code execution through improper memory management. The vulnerability is triggered locally, requiring an attacker to have access to the affected system or trick a user into opening a malicious database file. Successful exploitation permits arbitrary code execution in the context of the Access application, potentially enabling full system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Office Access
Timeline
- 2026-08-11: disclosed