CVE-2026-69529
8.8Microsoft · Microsoft 365 Apps for Enterprise, Access, Office
A heap-based buffer overflow in Microsoft Office Access allows an unauthenticated remote attacker to execute arbitrary code via a specially crafted file.
Executive summary
A heap-based buffer overflow vulnerability in Microsoft Office Access components, identified as CVE-2026-69529, poses a critical risk of remote code execution for affected enterprise environments.
Vulnerability
This vulnerability involves a heap-based buffer overflow (CWE-122) within the Microsoft Office Access engine. An unauthenticated attacker can trigger this flaw over a network, although successful exploitation requires user interaction to open a malicious file.
Business impact
The potential for remote code execution represents a severe threat to organizational security, as it allows attackers to gain full control over the compromised system. With a CVSS score of 8.8, this vulnerability carries a high risk of data exfiltration, lateral movement within the network, and complete system compromise. Organizations relying on Access for database management face significant operational risk if their environments are targeted.
Remediation
Immediate Action: Update all affected Microsoft Office and 365 installations to the specified fixed versions: 16.0.20326.20138 for Microsoft 365, 16.0.5569.1002 for Office 2016, 16.0.10417.20207 for Office 2019, and 16.0.14334.20906 for Office LTSC 2021.
Proactive Monitoring: Review endpoint security logs for unusual process execution patterns originating from Microsoft Access or related Office applications.
Compensating Controls: Deploy email filtering solutions to intercept malicious files and utilize endpoint protection platforms to block unauthorized file execution attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, this vulnerability should be treated with high priority. System administrators must identify all vulnerable instances of Microsoft Office and Access within the environment and apply the vendor-supplied patches immediately to mitigate the risk of exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Access Remote Code Execution Vulnerability Vendor advisory