ZeroHour

CVE-2026-78442

mass

Heap Buffer Overflow in Microsoft Windows OLE DB Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-78442 is a heap-based buffer overflow (CWE-122) in the Windows OLE DB data-access component, assigned by Microsoft ([email protected]). The flaw is exploitable over a network (AV:N) with low attack complexity, but the CVSS vector includes user interaction, indicating an attacker must get a user or service to process attacker-controlled data that reaches an OLE DB provider. Successful exploitation by an unauthorized attacker yields remote code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. Because OLE DB ships with Windows, virtually all Windows desktop and server deployments are potentially affected, with severity rated 8.8 (High). As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS shows only a 0.6% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-78442 as soon as it is published via Windows Update, prioritizing internet-facing and shared workstations; note that the advisory governs exactly which Windows builds are affected. Until patched, discourage users from opening untrusted files or connecting to untrusted data sources, since the user-interaction vector suggests crafted input triggers the flaw. No public PoC or in-the-wild exploitation is known, so routine patch-cycle remediation is reasonable, but monitor Microsoft's advisory for scope and exploitation updates.

Affected
Microsoft Windows OLE DB (Windows operating system component)
Estimated exposure
massHundreds of millions of Windows devices (OLE DB is bundled with Windows) — OLE DB is a core Windows data-access component present on essentially every Windows desktop and server in use worldwide (on the order of a billion Windows devices), though actual exploitability is limited to systems where a user or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.