CVE-2026-64911 – Microsoft Office Remote Code Execution Vulnerability
“A malicious Office file could turn a single user action into complete compromise of confidentiality, integrity, and availability.”
CVE-2026-64911 is a critical remote code execution vulnerability in affected Microsoft Office products. An integer overflow or wraparound can lead to a heap-based buffer overflow and allow an unauthorized attacker to execute code locally. Exploitation requires a user to open a malicious Office file, but the attacker does not require privileges. The Preview Pane is not an attack vector.
CVSS Score: 7.8.
SEVERITY: Critical.
THREAT:
An attacker can send a specially crafted Office file and convince a user to open it. Successful exploitation can execute code on the local machine and has the potential for high impact to confidentiality, integrity, and availability.
EXPLOITS:
The vulnerability is not publicly disclosed and is not known to be exploited. Exploit code maturity is classified as unproven, and exploitation is assessed as less likely. No confirmed public exploit, zero-day exploitation, or proof-of-concept exploit code is identified in the source information.
TECHNICAL SUMMARY:
CVE-2026-64911 involves integer overflow or wraparound and heap-based buffer overflow weaknesses in Microsoft Office. The attack has low complexity, requires no attacker privileges, and requires user interaction. An attacker must deliver a malicious Office file and persuade the victim to open it. Although categorized as remote code execution because the attacker can be remotely located, the actual exploitation is performed locally when the malicious content is opened. Successful exploitation can result in unauthorized code execution with high confidentiality, integrity, and availability impact.
EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Office 2019 (32-bit and 64-bit), Office LTSC 2021 and 2024 (32-bit and 64-bit), Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires a malicious Office file to be opened by a user.
BUSINESS IMPACT:
Successful exploitation could allow unauthorized code execution and cause significant loss of confidentiality, integrity, and availability. For organizations, a convincing malicious document could therefore expose sensitive information, enable unauthorized changes, or disrupt affected systems.
WORKAROUND:
No workaround or mitigation is identified. An official fix is available, making deployment of the applicable Office update the documented remediation.
URGENCY:
This vulnerability carries a Critical severity rating and can lead to remote code execution with high confidentiality, integrity, and availability impact. Although exploitation is assessed as less likely and no active exploitation is identified, affected Office installations should be updated promptly because opening a malicious document can trigger exploitation without requiring attacker privileges.
Key Details
- Affected Product
- Microsoft 365 Apps
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-122