Heap-based Buffer Overflow in Microsoft Office Affects Unauthorized Code Execution
CVE-2026-45474

8.4HIGH

What is CVE-2026-45474?

This vulnerability in Microsoft Office is a heap-based buffer overflow that could allow an attacker to execute arbitrary code on affected systems. By exploiting this flaw, unauthorized individuals can gain control over user environments, potentially leading to confidential data exposure or further attacks. It is crucial for users to apply the latest patches provided by Microsoft to mitigate these risks.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Office 2016 32-bit Systems 16.0.0 < 16.0.5556.1005

Microsoft Office 2019 32-bit Systems 19.0.0

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.