Junglewise Threat Intelligence

CVE-2026-69285: Microsoft Office heap-based buffer overflow

CVE-2026-69285 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used productivity suite for creating and editing documents, spreadsheets, and presentations. A heap-based buffer overflow vulnerability allows attackers to execute arbitrary code on affected systems through a network attack, potentially leading to complete system compromise, data theft, or malware installation.

Technical details

This is a heap-based buffer overflow vulnerability in Microsoft Office that allows remote code execution over a network. The vulnerability likely stems from improper bounds checking in memory allocation within the Office parsing or document processing components. The attack vector is network-based, requiring no special authentication or user interaction beyond opening a malicious document or interacting with a compromised service. An attacker can exploit this to execute arbitrary code with the privileges of the affected Office process, potentially leading to system compromise. Microsoft has issued security updates to address this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats