CVE-2026-69742
8.8Microsoft · Microsoft Office Publisher
An integer overflow vulnerability in Microsoft Office Publisher allows an unauthenticated remote attacker to execute arbitrary code via a specially crafted file.
Executive summary
An integer overflow flaw in Microsoft Office Publisher exposes multiple versions of Microsoft Office to potential remote code execution by unauthenticated attackers.
Vulnerability
This vulnerability is caused by an integer overflow or wraparound condition in Microsoft Office Publisher. An unauthenticated attacker can exploit this via network vectors to achieve remote code execution, though successful exploitation typically requires user interaction.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the victim's machine, potentially leading to a full system compromise. Given the CVSS score of 8.8, this represents a high risk to organizational data integrity and confidentiality. This flaw could be leveraged to deploy malware, exfiltrate sensitive documents, or facilitate lateral movement within the corporate network.
Remediation
Immediate Action: Apply the security updates provided by Microsoft in the official update guide to the versions listed above.
Proactive Monitoring: Monitor endpoint activity for suspicious processes spawned by the Publisher application, such as command shells or unauthorized network connections.
Compensating Controls: Ensure that email filtering solutions are configured to block or sandbox suspicious office document attachments, which serves as a critical defense against the required user interaction.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should prioritize the deployment of these patches across all affected Microsoft Office installations. Given the risk of remote code execution, delaying the patch cycle increases the window of vulnerability for potential weaponization of this flaw. Please consult the official Microsoft Security Update Guide for specific deployment instructions tailored to your software environment.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Publisher Remote Code Execution Vulnerability Vendor advisory