Junglewise Threat Intelligence

CVE-2026-64919: Microsoft Office Access stack-based buffer overflow

CVE-2026-64919 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a database management application used by many organizations to create and manage business data. A stack-based buffer overflow vulnerability in Access could allow an attacker with local access to run malicious code with the privileges of the user running the application, potentially leading to data theft, corruption, or system compromise.

Technical details

A stack-based buffer overflow vulnerability exists in Microsoft Office Access that can be triggered through specially crafted input. The vulnerability requires local access to the affected system and the ability to open a malicious file with Access. Successful exploitation allows arbitrary code execution in the context of the user running the application. The CVSS score of 7.8 reflects high severity; however, the attack vector is local, limiting widespread remote exploitation risk. Patches are expected to be available from Microsoft.

Affected products

  • Microsoft Office Access

Timeline

  • 2026-08-11: disclosed

References

Related threats