CVE-2026-69759
8.8Microsoft · Microsoft 365 Apps for Enterprise
A stack-based buffer overflow in Microsoft Office Word allows an unauthenticated, remote attacker to execute arbitrary code.
Executive summary
A critical stack-based buffer overflow vulnerability in Microsoft Office Word products poses a severe risk of remote code execution for affected users.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring within Microsoft Office Word. It allows an unauthenticated attacker to execute code over a network, provided the attacker can trick a user into opening a specially crafted file.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the victim machine with the privileges of the logged-in user. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to full system compromise, data exfiltration, or the deployment of ransomware within the enterprise environment.
Remediation
Immediate Action: Update all affected Microsoft Office installations to the specified fixed versions immediately via the Microsoft Update Catalog or internal deployment tools.
Proactive Monitoring: Monitor endpoint logs for suspicious child processes spawning from Microsoft Word (e.g., cmd.exe or powershell.exe) and review network traffic for unusual outbound connections from user workstations.
Compensating Controls: Utilize endpoint detection and response (EDR) solutions to block malicious file execution and ensure that macro security settings are configured to prevent the execution of untrusted content.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The high CVSS severity and the potential for remote code execution necessitate an immediate patching cycle across all endpoints running the affected versions of Microsoft Office. Security teams should prioritize the deployment of the provided vendor updates to eliminate the underlying buffer overflow condition and prevent potential exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Word Remote Code Execution Vulnerability Vendor advisory