Executive brief
Microsoft Office Access is a database management application used by organizations to store and manage business data. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer through a malicious file sent over a network, potentially compromising sensitive business data and system integrity.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office Access's file parsing logic. The vulnerability is triggered when processing specially crafted Access database files, allowing an attacker to overflow heap memory and gain control of program execution. The attack requires user interaction (opening a malicious file), but can be delivered remotely via email or web download. Successful exploitation enables arbitrary code execution with the privileges of the user running Access. Microsoft has released security updates addressing this vulnerability.
Affected products
- Microsoft Office Access
Timeline
- 2026-09-08: disclosed