CVE-2026-69759
massStack Buffer Overflow RCE in Microsoft Word (Office 2019-2024, Microsoft 365)
CVE-2026-69759 is a stack-based buffer overflow (CWE-121) in Microsoft Word, the word-processing component of Microsoft Office. Given the network attack vector combined with a user-interaction requirement in the CVSS vector, the flaw is most plausibly triggered by convincing a user to open a specially crafted Word document, at which point the overflow corrupts the stack and runs attacker-controlled code. A successful attack yields remote code execution with the victim user's privileges, with high impact on confidentiality, integrity, and availability of the endpoint. Users running Word within Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, Office 2021, and Office 2024 editions are in the affected population. As of the available data, the bug is not in CISA's KEV catalog, has no known public proof-of-concept, and carries a modest 0.8% EPSS probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.
What to do: Apply Microsoft's security updates for Word/Office covering Microsoft 365 Apps and Office 2019/2021/2024, checking Microsoft's advisory for the exact affected builds since version ranges are not specified in this data. Interim mitigations include warning users against opening Word documents from untrusted sources, as exploitation requires user interaction. If Office auto-updates are disabled on endpoints, manually trigger updates and verify the installed build is patched.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
| microsoft Word (component within the above Office editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.