ZeroHour

CVE-2026-78505

mass

Heap-Based Buffer Overflow in Microsoft Office Enables Network Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-78505 is a heap-based buffer overflow (CWE-122) in Microsoft Office that allows an unauthorized attacker to execute arbitrary code over a network. Per the CVSS vector, the flaw is reachable through network-facing processing with no privileges required, though attacker-supplied content requires user interaction (UI:R) to be processed, consistent with Office handling crafted files or content. Successful exploitation gives the attacker code execution in the context of the Office user, with high impact on confidentiality, integrity, and availability. The flaw affects Microsoft 365 Apps and Microsoft 365 as well as the perpetual Office 2016, 2019, 2021, and 2024 releases. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.8% chance of exploitation in the next 30 days.

What to do: Install the Microsoft security update addressing CVE-2026-78505 for all affected editions (Microsoft 365 Apps and Office 2016/2019/2021/2024) as soon as Microsoft's advisory provides the patched builds, and verify installed Office build numbers against the advisory. Until patched, restrict opening of untrusted Office files and attachments, and rely on Microsoft 365 attack surface reduction rules (for example blocking Office applications from creating child processes) to limit impact. Track Microsoft's advisory for specific patched version numbers, since none are included in the data available here.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Office is deployed across the global Windows user base; Microsoft 365 alone is reported to have 400M+ paid seats) — The affected products are mainstream Microsoft Office editions and Microsoft 365, whose combined installed base is measured in hundreds of millions of users, making this effectively all Office deployments until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.