CVE-2026-69477
massHeap Buffer Overflow in Microsoft Office Access Allows Local Code Execution
CVE-2026-69477 is a heap-based buffer overflow (CWE-122) in Microsoft Office Access, the database component of Microsoft Office. According to the CVSS vector, a low-privileged, authorized local attacker must also get user interaction (UI:R) to trigger the flaw, which is consistent with a crafted Access database or file being opened by the victim. Successful exploitation yields arbitrary code execution in the context of the local user, with high impact on confidentiality, integrity, and availability. Any environment running Microsoft Office Access is affected; the available data does not specify affected or fixed build numbers, so defenders must consult Microsoft's advisory for update details. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.4% (35th percentile).
What to do: Apply Microsoft's security update for Access as soon as it is available via Windows Update or the Microsoft 365 Apps update channel, and confirm the fixed build on the Microsoft Security Response Center advisory page for CVE-2026-69477, since this data does not list specific versions. In the interim, caution users against opening Access database files (.accdb/.mdb) from untrusted sources, given the user-interaction requirement. Monitor Microsoft's advisory for any change in exploitation status, as no public PoC or in-the-wild exploitation is currently known.
| Microsoft Office Access (Microsoft Access) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- 365 apps, access, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.