ZeroHour

CVE-2026-69778

mass

Heap Buffer Overflow in Microsoft Office Access Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-69778 is a heap-based buffer overflow (CWE-122) in Microsoft Access, the database application bundled with Microsoft Office and Microsoft 365. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the flaw is reachable over a network without special privileges but requires user interaction, most likely by convincing a user to open a maliciously crafted Access database file. Successful exploitation allows an unauthorized attacker to execute arbitrary code in the context of the user, with high impact on confidentiality, integrity, and availability (CVSS 8.8). Any user running Microsoft Access via supported Office or Microsoft 365 installations is affected. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.8% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for Access as soon as it is published through Microsoft's standard update channels (Microsoft Update, WSUS, or your endpoint management platform); specific patched build numbers are not listed in the available data. Until systems are patched, avoid opening .accdb/.mdb files from untrusted sources and remind users, since exploitation requires user interaction. Inventory your estate for Access deployments (e.g., Office Professional installs and Microsoft 365 E3/E5 seats) to prioritize patching.

Affected
Microsoft Office Access (Microsoft Access, the database component of Microsoft Office / Microsoft 365)
Estimated exposure
masstens of millions of users (Access ships with widespread Office/Microsoft 365 editions) — Microsoft Access is bundled in common Office professional editions and Microsoft 365 enterprise plans whose combined installed base is far above one million, so the potentially affected population is plausibly in the tens of millions,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, access, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.