Junglewise Threat Intelligence

CVE-2026-69477: Microsoft Office Access heap-based buffer overflow

CVE-2026-69477 · Severity: high · CVSS 7.3 · Published 2026-09-08

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a database management application used by many organizations to store and manage business data. A heap-based buffer overflow vulnerability allows an authorized user with local access to execute arbitrary code on the affected system, potentially compromising data confidentiality and system integrity.

Technical details

A heap-based buffer overflow exists in Microsoft Office Access due to improper bounds checking in a memory operation. The vulnerability requires an authorized user with local access to trigger the overflow, likely by opening a specially crafted Access file. Successful exploitation allows execution of arbitrary code with the privileges of the user running Access. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Office Access

Timeline

  • 2026-09-08: disclosed

References

Related threats