Heap-based buffer overflow in Microsoft products - CVE-2026-44824
Published: June 15, 2026
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft 365 Apps for Enterprise
Microsoft Office
Microsoft Office LTSC
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Microsoft Office. A remote attacker can trick a victim to open a specially crafted Office file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.