ZeroHour

CVE-2026-69739

mass

Out-of-bounds read in Microsoft Office allows network information disclosure

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-69739 is an out-of-bounds read (CWE-125) in Microsoft Office that lets an unauthorized attacker read memory beyond intended bounds and disclose information over a network. The CVSS vector scores this as a network attack (AV:N) requiring no privileges and no user interaction, though the available data does not specify the exact trigger mechanism. Successful exploitation yields confidentiality impact only (C:H with no integrity or availability impact), meaning an attacker gains access to data in process memory rather than code execution. Any environment running Microsoft 365 Apps or Office 2016, 2019, 2021, or 2024 is within the affected product scope. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.9% probability of exploitation within 30 days (57th percentile), indicating no known exploitation to date.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, checking Microsoft's advisory for the fixed build for each product and update channel, since Microsoft 365 Apps channels and Office 2016/2019/2021/2024 update paths differ. Until systems are patched, review how affected Office installations are exposed to network sources and treat environments handling sensitive data as higher priority. No workarounds, exploit code, or in-the-wild exploitation reports are documented in the data provided.

Affected
Microsoft 365 Apps
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of installations worldwide (global Microsoft Office installed base) — Microsoft Office and Microsoft 365 Apps run on the overwhelming majority of enterprise and consumer Windows desktops, with Microsoft 365 commercial seats alone reported in the hundreds of millions, so the plausible affected population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Vendors
microsoft
Products
365 apps, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.