CVE-2026-78524
massOut-of-bounds write RCE in Microsoft Office and Microsoft 365 Apps
CVE-2026-78524 is an out-of-bounds write (CWE-787) in Microsoft Office that allows an unauthorized attacker to execute code over a network. The attack path is network-reachable, but per the CVSS vector (UI:R) it requires user interaction, consistent with a victim's Office client processing attacker-supplied content such as a crafted file; no prior privileges are required. Successful exploitation yields code execution in the context of the Office application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Users and organizations running Microsoft 365 Apps, Microsoft 365, or Office 2016/2019/2021/2024 are affected; the source data does not include specific affected or fixed build numbers, so defenders should consult Microsoft's advisory for exact versions. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.8% probability of exploitation within 30 days (56th percentile), indicating no confirmed in-the-wild exploitation yet.
What to do: Prioritize applying the Office security updates published in Microsoft's advisory, focusing first on endpoints that routinely open documents from untrusted sources, and verify installed Microsoft 365 Apps/Office builds against the advisory's fixed versions (not included in this dataset). Until patched, reinforce handling of Office files from unknown origins — treat unexpected attachments and downloaded documents with suspicion and keep active content/macro policies restricted. Monitor Microsoft's advisory and your threat-intel feeds for a public PoC or KEV listing, which would raise patch urgency.
| microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.