Junglewise Threat Intelligence

CVE-2026-65661: Microsoft Office heap buffer overflow

CVE-2026-65661 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer when processing a specially crafted Office document, potentially leading to complete system compromise.

Technical details

A heap-based buffer overflow exists in Microsoft Office's document processing logic. The vulnerability occurs when Office parses a specially crafted malicious file, causing a buffer overwrite on the heap that can be leveraged for arbitrary code execution. The attack requires local execution or requires a user to open a malicious document. An attacker can achieve code execution in the context of the logged-in user, potentially gaining system-level access depending on user privileges. Microsoft has released security updates addressing this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats