Junglewise Threat Intelligence

CVE-2026-66807: Microsoft Office stack-based buffer overflow

CVE-2026-66807 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used productivity suite for creating and editing documents, spreadsheets, and presentations. A stack-based buffer overflow vulnerability allows an attacker to execute malicious code on a user's computer, potentially leading to data theft, system compromise, or installation of malware.

Technical details

A stack-based buffer overflow exists in Microsoft Office that can be exploited to execute arbitrary code with local privilege context. The vulnerability is triggered during document parsing or processing. An attacker must first trick a user into opening a specially crafted Office document to trigger the overflow. Once exploited, the attacker gains code execution on the affected system, allowing them to read/modify files, install malware, or pivot to other systems on the network. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats