CVE-2026-78505
massHeap-Based Buffer Overflow in Microsoft Office Enables Network Code Execution
CVE-2026-78505 is a heap-based buffer overflow (CWE-122) in Microsoft Office that allows an unauthorized attacker to execute arbitrary code over a network. Per the CVSS vector, the flaw is reachable through network-facing processing with no privileges required, though attacker-supplied content requires user interaction (UI:R) to be processed, consistent with Office handling crafted files or content. Successful exploitation gives the attacker code execution in the context of the Office user, with high impact on confidentiality, integrity, and availability. The flaw affects Microsoft 365 Apps and Microsoft 365 as well as the perpetual Office 2016, 2019, 2021, and 2024 releases. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.8% chance of exploitation in the next 30 days.
What to do: Install the Microsoft security update addressing CVE-2026-78505 for all affected editions (Microsoft 365 Apps and Office 2016/2019/2021/2024) as soon as Microsoft's advisory provides the patched builds, and verify installed Office build numbers against the advisory. Until patched, restrict opening of untrusted Office files and attachments, and rely on Microsoft 365 attack surface reduction rules (for example blocking Office applications from creating child processes) to limit impact. Track Microsoft's advisory for specific patched version numbers, since none are included in the data available here.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.