ZeroHour

CVE-2026-69742

mass

Integer Overflow RCE in Microsoft Office Publisher

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69742 is an integer overflow or wraparound flaw (CWE-190) in Microsoft Office Publisher that Microsoft rates High (CVSS 3.1: 8.8) and that allows an unauthenticated attacker to execute code over a network. The CVSS vector includes user interaction (UI:R), which is consistent with the classic Office attack pattern: the attacker sends a specially crafted Publisher document (for example by email) and code runs when the victim opens it. Successful exploitation executes the attacker's code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability — effectively full compromise of the endpoint. Any Microsoft Office installation that includes the Publisher component is potentially affected; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for affected and fixed builds. There is currently no evidence of exploitation: no public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for Publisher via the standard Office/Microsoft 365 update channels (Microsoft Update / Office Click-to-Run) and verify the fixed build number against Microsoft's advisory, since specific version ranges are not listed in the source data. Until patched, warn users not to open unsolicited or untrusted .pub files and consider blocking or stripping Publisher attachments at the mail gateway. Continue monitoring Microsoft's advisory and KEV/EPSS feeds for changes in exploitation status.

Affected
Microsoft Office Publisher
Estimated exposure
masslikely tens of millions of endpoints with Publisher installed (component of Microsoft Office/Microsoft 365 suites), though only endpoints that open untrusted… — Microsoft Office is deployed on hundreds of millions of business and consumer Windows devices and Publisher is bundled with many Office/Microsoft 365 commercial editions, so the number of installations containing the vulnerable component…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2019, office 2021, office 2024, publisher
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.