ZeroHour

CVE-2026-77898

mass

Heap-Based Buffer Overflow in Microsoft Office Enables Remote Code Execution

CVSS 3.1
7.5 high
EPSS
<1%p39
Published
()
Modified
AI analysis

Microsoft Office is affected by a heap-based buffer overflow (CWE-122) that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/AC:H/PR:N/UI:R) indicates exploitation requires user interaction and is of high attack complexity, consistent with a scenario in which a victim opens or processes specially crafted content in an Office application. A successful attack yields high impact to confidentiality, integrity, and availability on the affected system. Users of Microsoft 365 Apps, Microsoft 365, and the perpetual-license releases Office 2019, Office 2021, and Office 2024 are in scope, though specific vulnerable builds are not enumerated in the available data. There is no current evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

What to do: Monitor Microsoft's security advisory for this CVE to identify affected builds and apply the Office security update as soon as it is available, prioritizing users who regularly handle untrusted documents. Until patched, rely on Office Protected View policies, email attachment filtering, and user caution with unexpected files as interim mitigations. Defender teams should watch for Microsoft or third-party proof-of-concept code, since exploitation status may change quickly once a PoC appears.

Affected
Microsoft 365 Apps
Microsoft 365
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users/devices across the Office and Microsoft 365 installed base — Office and Microsoft 365 are among the most widely deployed productivity suites, with Microsoft publicly reporting hundreds of millions of paid Microsoft 365 seats and Office running on a very large share of business desktops, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.