ZeroHour

CVE-2026-69614

mass

Stack Buffer Overflow in Microsoft Office Access Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
AI analysis

Microsoft Office Access contains a stack-based buffer overflow (CWE-121) resulting from improper input validation (CWE-20) that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates no privileges are required but user interaction is, most plausibly by persuading a user to open a maliciously crafted Access database delivered via email, a download, or a network share. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, typically in the context of the user who opened the file. Any organization or individual running Microsoft Office with Access installed is potentially affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.9% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69614 via your standard Office/Microsoft 365 update channel or the Microsoft Update Catalog, and confirm coverage for your specific Office release in Microsoft's advisory since fixed versions are not listed in this data. Until patched, warn users not to open Access database files (e.g., .accdb) from untrusted senders or untrusted network locations, as user interaction is the required trigger. Inventory which endpoints have Access installed to prioritize patching and improve future exposure assessments.

Affected
Microsoft Office Access (Microsoft Access, the database component of Microsoft Office/Microsoft 365)
Estimated exposure
massmillions of users/installations (Access ships in widely deployed Microsoft 365/Office professional and enterprise suites) — Microsoft Office/Microsoft 365 is installed on hundreds of millions of devices and Access is bundled in common professional and enterprise suites, so even the subset of users with Access present plausibly exceeds one million; Microsoft…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, access, office 2019, office 2021, office 2024
Weakness
CWE-20, CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.