CVE-2026-77898
massHeap-Based Buffer Overflow in Microsoft Office Enables Remote Code Execution
Microsoft Office is affected by a heap-based buffer overflow (CWE-122) that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/AC:H/PR:N/UI:R) indicates exploitation requires user interaction and is of high attack complexity, consistent with a scenario in which a victim opens or processes specially crafted content in an Office application. A successful attack yields high impact to confidentiality, integrity, and availability on the affected system. Users of Microsoft 365 Apps, Microsoft 365, and the perpetual-license releases Office 2019, Office 2021, and Office 2024 are in scope, though specific vulnerable builds are not enumerated in the available data. There is no current evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Monitor Microsoft's security advisory for this CVE to identify affected builds and apply the Office security update as soon as it is available, prioritizing users who regularly handle untrusted documents. Until patched, rely on Office Protected View policies, email attachment filtering, and user caution with unexpected files as interim mitigations. Defender teams should watch for Microsoft or third-party proof-of-concept code, since exploitation status may change quickly once a PoC appears.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.