CVE-2026-69742

8.8

Microsoft · Microsoft Office Publisher

An integer overflow vulnerability in Microsoft Office Publisher allows an unauthenticated remote attacker to execute arbitrary code via a specially crafted file.

Executive summary

An integer overflow flaw in Microsoft Office Publisher exposes multiple versions of Microsoft Office to potential remote code execution by unauthenticated attackers.

Vulnerability

This vulnerability is caused by an integer overflow or wraparound condition in Microsoft Office Publisher. An unauthenticated attacker can exploit this via network vectors to achieve remote code execution, though successful exploitation typically requires user interaction.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the victim's machine, potentially leading to a full system compromise. Given the CVSS score of 8.8, this represents a high risk to organizational data integrity and confidentiality. This flaw could be leveraged to deploy malware, exfiltrate sensitive documents, or facilitate lateral movement within the corporate network.

Remediation

Immediate Action: Apply the security updates provided by Microsoft in the official update guide to the versions listed above.

Proactive Monitoring: Monitor endpoint activity for suspicious processes spawned by the Publisher application, such as command shells or unauthorized network connections.

Compensating Controls: Ensure that email filtering solutions are configured to block or sandbox suspicious office document attachments, which serves as a critical defense against the required user interaction.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of these patches across all affected Microsoft Office installations. Given the risk of remote code execution, delaying the patch cycle increases the window of vulnerability for potential weaponization of this flaw. Please consult the official Microsoft Security Update Guide for specific deployment instructions tailored to your software environment.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources