CVE-2026-69442
massHeap-Based Buffer Overflow in Microsoft Office Enables Remote Code Execution
CVE-2026-69442 is a heap-based buffer overflow (CWE-122) in Microsoft Office that an unauthorized attacker can trigger over a network to execute code. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R), exploitation requires user interaction — consistent with the typical Office RCE pattern of a user being enticed into opening or interacting with attacker-supplied content — but the data does not specify the exact trigger. A successful attack yields high impact on confidentiality, integrity, and availability, i.e., arbitrary code execution in the context of the affected Office user. Any organization or individual running Microsoft Office is potentially affected; the data provides no specific affected version ranges, so defenders should consult Microsoft's advisory for the exact list. There are currently no signs of exploitation: no known in-the-wild abuse, no public proof-of-concept, no CISA KEV listing, and a modest EPSS of 0.8% (56th percentile) for exploitation within 30 days.
What to do: Track Microsoft's advisory for CVE-2026-69442 and apply the Office security update as soon as it is released, prioritizing workstations where users routinely open untrusted documents. Until patched, discourage or sandbox the opening of Office files from untrusted sources (e.g., via email attachment policies and attack-surface-reduction rules). Because no affected version ranges are given in this data, verify applicability against the versions in your estate before and after remediation.
| Microsoft Office | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.