Junglewise Threat Intelligence

CVE-2026-77898: Microsoft Office heap-based buffer overflow

CVE-2026-77898 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Microsoft Office, a widely-used productivity suite for creating documents, spreadsheets, and presentations, contains a heap-based buffer overflow vulnerability. An attacker can exploit this flaw by sending a specially crafted file over the network, potentially allowing them to execute arbitrary code on a user's computer without authorization. This could lead to data theft, system compromise, or further malware installation.

Technical details

A heap-based buffer overflow exists in Microsoft Office that allows remote code execution without authentication. The vulnerability is reachable over the network, likely triggered by processing a malicious document file. An attacker can craft a specially formatted Office document that triggers the overflow, enabling arbitrary code execution in the context of the user running Office. The attack does not require user interaction beyond opening the malicious file. Microsoft has issued patches to address this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats