CVE-2026-78442
massHeap Buffer Overflow in Microsoft Windows OLE DB Enables Remote Code Execution
CVE-2026-78442 is a heap-based buffer overflow (CWE-122) in the Windows OLE DB data-access component, assigned by Microsoft ([email protected]). The flaw is exploitable over a network (AV:N) with low attack complexity, but the CVSS vector includes user interaction, indicating an attacker must get a user or service to process attacker-controlled data that reaches an OLE DB provider. Successful exploitation by an unauthorized attacker yields remote code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. Because OLE DB ships with Windows, virtually all Windows desktop and server deployments are potentially affected, with severity rated 8.8 (High). As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS shows only a 0.6% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-78442 as soon as it is published via Windows Update, prioritizing internet-facing and shared workstations; note that the advisory governs exactly which Windows builds are affected. Until patched, discourage users from opening untrusted files or connecting to untrusted data sources, since the user-interaction vector suggests crafted input triggers the flaw. No public PoC or in-the-wild exploitation is known, so routine patch-cycle remediation is reasonable, but monitor Microsoft's advisory for scope and exploitation updates.
| Microsoft Windows OLE DB (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.