ZeroHour

CVE-2026-69442

mass

Heap-Based Buffer Overflow in Microsoft Office Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69442 is a heap-based buffer overflow (CWE-122) in Microsoft Office that an unauthorized attacker can trigger over a network to execute code. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R), exploitation requires user interaction — consistent with the typical Office RCE pattern of a user being enticed into opening or interacting with attacker-supplied content — but the data does not specify the exact trigger. A successful attack yields high impact on confidentiality, integrity, and availability, i.e., arbitrary code execution in the context of the affected Office user. Any organization or individual running Microsoft Office is potentially affected; the data provides no specific affected version ranges, so defenders should consult Microsoft's advisory for the exact list. There are currently no signs of exploitation: no known in-the-wild abuse, no public proof-of-concept, no CISA KEV listing, and a modest EPSS of 0.8% (56th percentile) for exploitation within 30 days.

What to do: Track Microsoft's advisory for CVE-2026-69442 and apply the Office security update as soon as it is released, prioritizing workstations where users routinely open untrusted documents. Until patched, discourage or sandbox the opening of Office files from untrusted sources (e.g., via email attachment policies and attack-surface-reduction rules). Because no affected version ranges are given in this data, verify applicability against the versions in your estate before and after remediation.

Affected
Microsoft Office
Estimated exposure
masson the order of hundreds of millions of users/devices (Office's install base spans Microsoft 365 commercial seats plus consumer desktop installs) — Microsoft Office is deployed across hundreds of millions of Microsoft 365 commercial users and consumer desktop installations, so an Office-wide flaw is potentially mass-impact, though the truly affected version ranges are not specified in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.