Junglewise Threat Intelligence

CVE-2026-64920: Microsoft Office Access heap-based buffer overflow

CVE-2026-64920 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a database management tool used for storing and managing organizational data. A heap-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Access, potentially compromising sensitive business data and system integrity.

Technical details

A heap-based buffer overflow exists in Microsoft Office Access that can be exploited through a maliciously crafted database file or input. The vulnerability requires local access to the system and user interaction to open a malicious file. Successful exploitation allows an attacker to execute arbitrary code in the context of the user running Access, potentially leading to system compromise. A patch is available through Microsoft Security Updates.

Affected products

  • Microsoft Office Access

Timeline

  • 2026-08-11: disclosed

References

Related threats