ZeroHour

CVE-2026-69529

mass

Heap-Based Buffer Overflow in Microsoft Access Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-69529 is a heap-based buffer overflow (CWE-122) in Microsoft Access, the database component of Microsoft Office/Microsoft 365, which Microsoft rates as remotely exploitable with no privileges required (CVSS 8.8). The CVSS vector requires user interaction (UI:R), indicating the victim must be induced to open or process attacker-supplied content in Access rather than the flaw being reachable from a headless service. Successful exploitation yields arbitrary code execution running with the victim user's privileges, with high impact on confidentiality, integrity, and availability (S:U, C:H/I:H/A:H). Any organization running an affected Microsoft Office/Microsoft 365 build that includes Access is potentially affected. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days (45th percentile).

What to do: Check installed Office/Access versions against the affected-products table in the Microsoft MSRC advisory and apply the vendor security update that fixes CVE-2026-69529 as soon as it is available. Until patched, caution users against opening unsolicited database files or other attacker-supplied content in Access, since user interaction is required for exploitation. Note that no in-the-wild exploitation or public PoC is known, but Microsoft RCE flaws of this class are typically exploited quickly once details circulate, so treat patching as a priority.

Affected
Microsoft Access (component of Microsoft Office / Microsoft 365)
Estimated exposure
massplausibly tens of millions of installations (Access ships as a component in widely deployed Microsoft Office/Microsoft 365 suites; Office's installed base… — Microsoft's Office/Microsoft 365 installed base runs to hundreds of millions of devices and Access is bundled in common Office suites, so the potentially affected population is very large even though exact Access install counts are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, access, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.