Executive brief
Microsoft Office Access is a database management application used by many organizations to store and manage business data. A heap-based buffer overflow vulnerability allows an authorized user with local access to execute arbitrary code on the affected system, potentially compromising data confidentiality and system integrity.
Technical details
A heap-based buffer overflow exists in Microsoft Office Access due to improper bounds checking in a memory operation. The vulnerability requires an authorized user with local access to trigger the overflow, likely by opening a specially crafted Access file. Successful exploitation allows execution of arbitrary code with the privileges of the user running Access. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Office Access
Timeline
- 2026-09-08: disclosed