CVE-2026-66807 – Microsoft Office Graphics Component Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a simple file-opening action into code execution with high impact to confidentiality, integrity, and availability.”

CVE-2026-66807 is a stack-based buffer overflow vulnerability in Microsoft Office that can allow an unauthorized attacker to execute code locally. Exploitation requires a user to open a malicious Office file, and the Preview Pane is also identified as an attack vector. No privileges are required. The vulnerability is not publicly disclosed and is not reported as exploited.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
An attacker can send a specially crafted Office file and convince a user to open it. Successful exploitation can result in code execution with high impact to confidentiality, integrity, and availability. The attack complexity is low and no privileges are required, although user interaction is necessary.

EXPLOITS:
No exploitation is reported, and the vulnerability is not publicly disclosed. Exploit code maturity is classified as Unproven, so the source does not confirm a public exploit, zero-day exploitation, or proof-of-concept exploit code.

TECHNICAL SUMMARY:
The vulnerability is caused by a stack-based buffer overflow (CWE-121) in the Microsoft Office Graphics Component. A malicious Office file can trigger the vulnerability when processed locally, including through the Preview Pane. Although the vulnerability title describes remote code execution, the CVSS attack vector is Local because exploitation requires code to be executed from the local machine. Successful exploitation allows code execution and can have high confidentiality, integrity, and availability impact.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires a malicious Office file to be opened or processed through the Preview Pane.

BUSINESS IMPACT:
Successful exploitation could allow attacker-controlled code to run on affected systems, putting sensitive information, data integrity, and system availability at risk. In an organization, a convincing malicious document could turn routine Office file handling into a system-compromise opportunity.

WORKAROUND:
No mitigations or workarounds are specified. An official fix is identified as the remediation.

URGENCY:
This vulnerability is rated Critical and can lead to code execution with high confidentiality, integrity, and availability impact. Organizations should prioritize deployment of the official fix, particularly because exploitation has low attack complexity, requires no privileges, and can involve malicious Office documents or the Preview Pane.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.