CVE-2026-65664 – Microsoft Office Graphics Component Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn one user action into code execution, putting sensitive data and system integrity at risk.”

CVE-2026-65664 is a heap-based buffer overflow vulnerability in Microsoft Office that can allow an unauthorized attacker to execute code locally. Exploitation requires a user to open a malicious Office file supplied by an attacker. No privileges are required, but user interaction is required. The Preview Pane is not an attack vector.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
Successful exploitation can result in remote code execution, with high potential impact to confidentiality, integrity, and availability. The attack has low complexity and requires no privileges, although the targeted user must be convinced to open a malicious Office file.

EXPLOITS:
The vulnerability is not publicly disclosed and is not known to be exploited. Exploit code maturity is classified as Unproven. The source does not confirm the existence of public exploit code, zero-day exploitation, or proof-of-concept code.

TECHNICAL SUMMARY:
CVE-2026-65664 is caused by a heap-based buffer overflow in the Microsoft Office Graphics Component. An attacker can send a specially crafted malicious Office file and convince a user to open it. Although the vulnerability is categorized as remote code execution because the attacker can be remote, the actual attack vector is local: the malicious content must be executed from the local machine. Successful exploitation can allow unauthorized code execution and cause high confidentiality, integrity, and availability impact. Attack complexity is low, no privileges are required, and user interaction is required.

EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Microsoft Office 2019 (32-bit and 64-bit), Microsoft Office LTSC 2021 and 2024 (32-bit and 64-bit), Microsoft Office 365 for Mac, and Microsoft Office LTSC for Mac 2021 and 2024. Exploitation requires the user to open a malicious Office file.

BUSINESS IMPACT:
Successful exploitation could allow an attacker to execute code and compromise sensitive information, alter data, or disrupt system availability. For organizations, a convincing malicious document could turn a routine file-opening action into a serious endpoint compromise.

WORKAROUND:
No workaround or mitigation is identified. An official fix is listed as the remediation.

URGENCY:
This vulnerability carries a Critical severity rating and can result in code execution with high confidentiality, integrity, and availability impact. Although exploitation is assessed as less likely and no exploitation is currently identified, organizations should prioritize deployment of the official fix because exploitation requires no privileges and has low attack complexity.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.