ZeroHour

CVE-2026-69477

mass

Heap Buffer Overflow in Microsoft Office Access Allows Local Code Execution

CVSS 3.1
7.3 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-69477 is a heap-based buffer overflow (CWE-122) in Microsoft Office Access, the database component of Microsoft Office. According to the CVSS vector, a low-privileged, authorized local attacker must also get user interaction (UI:R) to trigger the flaw, which is consistent with a crafted Access database or file being opened by the victim. Successful exploitation yields arbitrary code execution in the context of the local user, with high impact on confidentiality, integrity, and availability. Any environment running Microsoft Office Access is affected; the available data does not specify affected or fixed build numbers, so defenders must consult Microsoft's advisory for update details. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.4% (35th percentile).

What to do: Apply Microsoft's security update for Access as soon as it is available via Windows Update or the Microsoft 365 Apps update channel, and confirm the fixed build on the Microsoft Security Response Center advisory page for CVE-2026-69477, since this data does not list specific versions. In the interim, caution users against opening Access database files (.accdb/.mdb) from untrusted sources, given the user-interaction requirement. Monitor Microsoft's advisory for any change in exploitation status, as no public PoC or in-the-wild exploitation is currently known.

Affected
Microsoft Office Access (Microsoft Access)
Estimated exposure
masstens of millions of Windows users with Microsoft Access installed (Access ships in Microsoft 365 Apps for business/enterprise and Office professional suites… — Microsoft Office/Microsoft 365 has an installed base in the hundreds of millions of commercial seats, and Access is bundled in many enterprise and professional SKUs on Windows, so the order of magnitude of potentially affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, access, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.