SB20260812236 - Multiple vulnerabilities in Microsoft Access
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: CVE-2026-64906)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a victim and convince them to open it to execute arbitrary code.
User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.
2) Stack-based buffer overflow (CVE-ID: CVE-2026-64912)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.
User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-64908)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.
User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.
4) Heap-based buffer overflow (CVE-ID: CVE-2026-64914)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.
The Preview Pane is not an attack vector for this vulnerability.
5) Heap-based buffer overflow (CVE-ID: CVE-2026-64920)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.
User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.
6) Stack-based buffer overflow (CVE-ID: CVE-2026-64919)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in Microsoft Office Access when parsing a specially crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.
User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64906
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64912
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64908
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64914
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64920
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-64919
- https://www.microsoft.com/en-us/download/details.aspx?id=108771