CVE-2026-64903 – Microsoft Office Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a routine document-opening action into code execution with high impact to confidentiality, integrity, and availability.”

CVE-2026-64903 is a Critical Microsoft Office remote code execution vulnerability involving integer overflow or wraparound and a heap-based buffer overflow. An unauthorized attacker can send a malicious Office file and convince a user to open it, enabling code execution on the local machine. The Preview Pane is also identified as an attack vector. The vulnerability requires no attacker privileges but does require user interaction.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
An attacker could use a specially crafted Microsoft Office file to trigger the vulnerability and execute code locally. Successful exploitation carries High confidentiality, integrity, and availability impacts. Attack complexity is Low, and no privileges are required, increasing the potential threat from malicious documents.

EXPLOITS:
This vulnerability is not publicly disclosed and is not reported as exploited. Exploit code maturity is Unproven, and exploitation is assessed as Less Likely. No confirmed public exploit, zero-day exploitation, or proof-of-concept exploit code is identified.

TECHNICAL SUMMARY:
CVE-2026-64903 involves an integer overflow or wraparound and heap-based buffer overflow in Microsoft Office. An attacker can create a malicious Office file and convince a user to open it. The Preview Pane can also act as an attack vector. Although the CVSS attack vector is Local, “Remote” in the vulnerability title refers to the attacker's location; exploitation itself requires code to be executed from the local machine. Successful exploitation can result in arbitrary code execution with High impact to confidentiality, integrity, and availability.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit editions of Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires a malicious Office file and user interaction. No attacker privileges are required.

BUSINESS IMPACT:
Successful exploitation could allow unauthorized code execution on affected systems, potentially exposing sensitive information, altering data, or disrupting system availability. In organizations where Office documents are routinely exchanged, a convincing malicious document could create a significant security incident.

WORKAROUND:
No workaround or mitigation is identified. An official fix is identified as the remediation.

URGENCY:
This vulnerability is rated Critical and can result in remote code execution with High confidentiality, integrity, and availability impacts. Organizations should prioritize deployment of the official fix across affected Microsoft Office installations, particularly because exploitation has Low attack complexity and requires no attacker privileges.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.