ZeroHour

CVE-2026-69759

mass

Stack Buffer Overflow RCE in Microsoft Word (Office 2019-2024, Microsoft 365)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69759 is a stack-based buffer overflow (CWE-121) in Microsoft Word, the word-processing component of Microsoft Office. Given the network attack vector combined with a user-interaction requirement in the CVSS vector, the flaw is most plausibly triggered by convincing a user to open a specially crafted Word document, at which point the overflow corrupts the stack and runs attacker-controlled code. A successful attack yields remote code execution with the victim user's privileges, with high impact on confidentiality, integrity, and availability of the endpoint. Users running Word within Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, Office 2021, and Office 2024 editions are in the affected population. As of the available data, the bug is not in CISA's KEV catalog, has no known public proof-of-concept, and carries a modest 0.8% EPSS probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.

What to do: Apply Microsoft's security updates for Word/Office covering Microsoft 365 Apps and Office 2019/2021/2024, checking Microsoft's advisory for the exact affected builds since version ranges are not specified in this data. Interim mitigations include warning users against opening Word documents from untrusted sources, as exploitation requires user interaction. If Office auto-updates are disabled on endpoints, manually trigger updates and verify the installed build is patched.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
microsoft Word (component within the above Office editions)
Estimated exposure
masshundreds of millions of users (Word ships with an Office installed base in the high hundreds of millions; Microsoft 365 alone has ~400M+ paid seats) — The estimate is based on Microsoft 365's publicly reported ~400M+ paid seats and the very large legacy Office/Word desktop installed base across 2019/2021/2024 editions, which plausibly puts the exposed user population in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.