CVE-2026-69285

8.8

Microsoft · Microsoft 365 Apps for Enterprise, Office 2016, 2019, LTSC 2021, LTSC 2024

A heap-based buffer overflow in Microsoft Office allows an unauthenticated, remote attacker to execute arbitrary code via network-based vectors.

Executive summary

A heap-based buffer overflow vulnerability in multiple Microsoft Office products enables remote code execution, posing a critical risk to organizational systems.

Vulnerability

The flaw is a heap-based buffer overflow (CWE-122) triggered when the software processes malformed data. This vulnerability allows an unauthenticated attacker to achieve remote code execution, provided they can successfully interact with a user or system process via the network.

Business impact

Successful exploitation of this vulnerability permits unauthorized code execution, which may lead to a complete compromise of the host system, data exfiltration, or the deployment of persistent malware. With a CVSS score of 8.8, the vulnerability is classified as High, reflecting the severe potential for impact on confidentiality, integrity, and availability of business information.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately by deploying the corresponding fixed versions listed in the enrichment data for your specific Office product.

Proactive Monitoring: Monitor endpoint processes for unusual memory consumption or unexpected spawning of child processes from Office applications, which may indicate attempted exploitation.

Compensating Controls: Utilize endpoint detection and response tools to block execution of suspicious macro-enabled files or network traffic originating from untrusted sources directed at Office components.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS severity and the potential for total system compromise via remote code execution, organizations should prioritize patching across all affected Microsoft Office installations. Please verify your current version against the fixed versions provided in the metadata and initiate an emergency update cycle to eliminate this exposure.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources