CVE-2026-70130 – Microsoft Office Remote Code Execution Vulnerability
“A memory corruption flaw in Microsoft Office could give an attacker the ability to run code with serious consequences for data and systems.”
CVE-2026-70130 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in Microsoft Office. An unauthorized attacker can exploit the flaw locally to execute code. Successful exploitation can have a high impact on confidentiality, integrity, and availability.
CVSS Score: 8.4.
SEVERITY: Critical.
THREAT:
The vulnerability creates a significant code execution threat through memory corruption in Microsoft Office. Attack complexity is low, and exploitation requires neither privileges nor user interaction. Successful exploitation could compromise sensitive information, alter data, or disrupt affected systems.
EXPLOITS:
The vulnerability is not publicly disclosed and is not reported as exploited. Exploit code maturity is classified as unproven, and exploitation is assessed as less likely. No confirmed public exploit, zero-day exploitation, or proof-of-concept exploit code is identified.
TECHNICAL SUMMARY:
CVE-2026-70130 is a heap-based buffer overflow, identified as CWE-122, affecting Microsoft Office. The flaw involves improper handling of memory on the heap and can allow an unauthorized attacker to execute code locally. The attack has low complexity, requires no privileges, and requires no user interaction. The security impact is rated high for confidentiality, integrity, and availability, meaning successful exploitation could expose information, modify data, and affect system availability.
EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise for 32-bit and 64-bit systems; Microsoft Office 2019 for 32-bit and 64-bit editions; Microsoft Office LTSC 2021 for 32-bit and 64-bit editions; and Microsoft Office LTSC 2024 for 32-bit and 64-bit editions. Exploitation uses a local attack vector with low attack complexity and requires no privileges or user interaction.
BUSINESS IMPACT:
Successful exploitation could enable unauthorized code execution and lead to loss of confidentiality, integrity, and availability. For organizations, this creates risks to sensitive business information, system trust, and operational continuity. A successful compromise could turn an Office installation into an entry point for broader security consequences.
WORKAROUND:
No workaround or mitigation is identified. An official fix is available, so affected Microsoft Office installations should be updated using the applicable Click-to-Run servicing mechanism.
URGENCY:
This vulnerability is rated Critical and can result in remote code execution with high confidentiality, integrity, and availability impact. Although exploitation is assessed as less likely and no active exploitation is reported, its low attack complexity and lack of privilege or user-interaction requirements make timely deployment important.
Key Details
- Affected Product
- Microsoft 365 Apps
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-122