CVE-2026-64910 – Microsoft Office Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

"A malicious Office file could turn one user action into high-impact code execution, putting sensitive data and system integrity at risk."

CVE-2026-64910 is a critical Microsoft Office remote code execution vulnerability caused by an untrusted pointer dereference. An attacker can send a malicious Office file and convince a user to open it, which could allow unauthorized code execution on the local machine. The vulnerability requires no attacker privileges but does require user interaction. It is not publicly disclosed or known to be exploited.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
Successful exploitation can provide code execution with high impact to confidentiality, integrity, and availability. The attack has low complexity and requires no privileges, although the targeted user must open a malicious Office file.

EXPLOITS:
The vulnerability is not publicly disclosed and is not known to be exploited. Exploit code maturity is classified as unproven, so the source does not confirm a public exploit, zero-day exploitation, or proof-of-concept exploit code.

TECHNICAL SUMMARY:
The vulnerability is caused by an untrusted pointer dereference (CWE-822) in Microsoft Office. Exploitation requires an attacker to deliver a malicious Office file and convince the targeted user to open it. Although classified as remote code execution because the attacker can be remote, the actual attack vector is local because the malicious content must be executed on the victim's machine. Successful exploitation allows an unauthorized attacker to execute code locally, with high potential impact to confidentiality, integrity, and availability. The Preview Pane is not an attack vector.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires a user to open a malicious Office file.

BUSINESS IMPACT:
Successful exploitation could allow attacker-controlled code to run on an affected system, potentially exposing sensitive information, compromising data integrity, and disrupting system availability. A malicious Office document used in phishing or similar delivery could therefore create a significant security incident when opened.

WORKAROUND:
No workaround or mitigation is identified. An official fix is available, so affected Office installations should be updated.

URGENCY:
This vulnerability is rated Critical and can result in remote code execution with high confidentiality, integrity, and availability impact. Organizations should prioritize deployment of the official fix across affected Microsoft Office installations even though exploitation is currently assessed as less likely and no active exploitation is identified.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-822
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.