ZeroHour

CVE-2026-69285

mass

Heap-Based Buffer Overflow RCE in Microsoft Office and Microsoft 365 Apps

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-69285 is a heap-based buffer overflow (CWE-122) in Microsoft Office that an unauthorized attacker can exploit over a network to execute arbitrary code. Per the CVSS vector (AV:N/PR:N/UI:R), exploitation requires no privileges or special conditions but does require user interaction, which typically means the victim must open or interact with attacker-supplied content such as a crafted document. A successful attack would let the attacker run code with the victim user's privileges, with high impact on confidentiality, integrity, and availability. Affected products include Microsoft 365 Apps and the perpetual editions Office 2016, Office 2019, Office 2021, and Office 2024. There is currently no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation within 30 days, so there is no confirmed in-the-wild exploitation yet.

What to do: Track Microsoft's advisory for CVE-2026-69285 and apply the released Office security updates to Microsoft 365 Apps and Office 2016/2019/2021/2024 as soon as they are available, confirming all workstation Office builds are fully patched. Until patched, discourage users from opening untrusted Office documents and attachments, since exploitation requires user interaction. With no public PoC or known exploitation and a low EPSS score, a prompt-but-standard patch cadence is reasonable, but monitor for new exploit releases given heap-overflow RCEs in Office are commonly weaponized.

Affected
Microsoft 365 Apps
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users/devices (Office/Microsoft 365 is the dominant office suite) — Microsoft Office and Microsoft 365 are deployed on well over a billion devices worldwide with hundreds of millions of Microsoft 365 commercial seats, so any exploitable flaw in these products affects a mass-scale installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.