Junglewise Threat Intelligence

CVE-2026-78505: Microsoft Office heap-based buffer overflow

CVE-2026-78505 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office is a suite of productivity applications used across enterprises to create and edit documents, spreadsheets, and presentations. A heap-based buffer overflow vulnerability in Office could allow an attacker to execute arbitrary code on an affected system simply by sending a specially crafted file over the network, potentially leading to data theft, system compromise, or lateral movement through an organization.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office that does not properly validate buffer boundaries during memory operations. The vulnerability can be triggered remotely when a user opens or processes a malicious Office document, without requiring authentication. An attacker can craft a specially formatted file that, when processed by Office, overflows a heap buffer and overwrites adjacent memory, achieving code execution with the privileges of the user running Office. A patch is expected from Microsoft through their regular security update cycle.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats