CVE-2026-64909 – Microsoft Office Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a routine document open into code execution with high impact to confidentiality, integrity, and availability.”

CVE-2026-64909 is a critical remote code execution vulnerability in Microsoft Office involving integer underflow, out-of-bounds read, and heap-based buffer overflow weaknesses. An attacker can send a specially crafted Office file and convince a user to open it. The Preview Pane is also identified as an attack vector. Although the vulnerability is described as remote code execution because the attacker may be remote, exploitation itself occurs locally on the affected system.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
An unauthorized attacker could use a malicious Office file to execute code on an affected system. Attack complexity is low and no privileges are required, but user interaction is required. Successful exploitation can have a high impact on confidentiality, integrity, and availability.

EXPLOITS:
This vulnerability is not publicly disclosed and is not known to be exploited. Exploit code maturity is classified as Unproven, and exploitation is assessed as Less Likely. The source does not confirm the existence of public exploit code, a zero-day exploit, or proof-of-concept code.

TECHNICAL SUMMARY:
The vulnerability is associated with integer underflow or wraparound (CWE-191), out-of-bounds read (CWE-125), and heap-based buffer overflow (CWE-122) weaknesses in Microsoft Office. An attacker must send a malicious Office file and convince a user to open it. The Preview Pane can also provide an attack vector. The CVSS attack vector is Local, with low attack complexity, no privileges required, required user interaction, and unchanged scope. Successful exploitation allows code execution and can result in high confidentiality, integrity, and availability impact.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires interaction with a malicious Office file, including through the Preview Pane.

BUSINESS IMPACT:
Successful exploitation could allow attacker-controlled code to run on an affected endpoint, creating significant risk to sensitive information, system integrity, and business operations. Compromise of Office endpoints could expose business data, permit unauthorized changes, or disrupt system availability.

WORKAROUND:
No workaround or mitigation is identified. An official fix is available, making patch deployment the documented remediation path.

URGENCY:
This vulnerability carries a Critical severity rating and can lead to remote code execution with high confidentiality, integrity, and availability impact. Although exploitation is assessed as Less Likely and no active exploitation is identified, organizations should prioritize deployment of the official fix because a malicious Office file can trigger a high-impact compromise with low attack complexity and no attacker privileges required.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.