Executive brief
Microsoft Office Access is a database application commonly used for data management in business environments. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's system via a specially crafted file, potentially compromising confidentiality, integrity, and availability of business data.
Technical details
A stack-based buffer overflow exists in Microsoft Office Access that can be exploited by network-based attack vectors. The vulnerability stems from insufficient input validation in a buffer handling routine, allowing an attacker to overwrite stack memory and redirect program execution. Exploitation does not require prior authentication or elevated privileges, though user interaction (opening a malicious file) is likely required. A successful exploit results in arbitrary code execution with the privileges of the affected user.
Affected products
- Microsoft Office Access
Timeline
- 2026-09-08: disclosed