SB20260812236 - Multiple vulnerabilities in Microsoft Access



SB20260812236 - Multiple vulnerabilities in Microsoft Access

Published: August 12, 2026

Security Bulletin ID SB20260812236
CSH Severity
High
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Heap-based buffer overflow (CVE-ID: CVE-2026-64906)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a victim and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


2) Stack-based buffer overflow (CVE-ID: CVE-2026-64912)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


3) Heap-based buffer overflow (CVE-ID: CVE-2026-64908)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


4) Heap-based buffer overflow (CVE-ID: CVE-2026-64914)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.

The Preview Pane is not an attack vector for this vulnerability.


5) Heap-based buffer overflow (CVE-ID: CVE-2026-64920)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Microsoft Office Access when parsing a crafted Office file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.

User interaction is required to open a crafted file, and the Preview Pane is not an attack vector.


6) Stack-based buffer overflow (CVE-ID: CVE-2026-64919)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in Microsoft Office Access when parsing a specially crafted Office file. A remote attacker can send a specially crafted file to a user and convince them to open it to execute arbitrary code.

User interaction is required to open the crafted file, and the Preview Pane is not an attack vector.


Remediation

Install update from vendor's website.