Heap-based buffer overflow in Microsoft Office for macOS and Microsoft PowerPoint - CVE-2026-55043
Published: July 17, 2026
Vulnerability identifier: #VU138242
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55043
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office PowerPoint when parsing a crafted Office file. A remote attacker can send a specially crafted Office file to execute arbitrary code.
User interaction is required to open the crafted file.
Affected software
Microsoft Office for macOS
Microsoft PowerPoint
Microsoft PowerPoint
How to mitigate CVE-2026-55043
Install security update from vendor's website.
Microsoft Office for macOS - update to 16.111.26071215
Microsoft PowerPoint - update to 16.0.5561.1000
Microsoft PowerPoint - update to 16.0.5561.1000