Stack-based buffer overflow in Microsoft products - CVE-2026-69614

 

Stack-based buffer overflow in Microsoft products - CVE-2026-69614

Published: September 8, 2026


Vulnerability identifier: #VU147847
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69614
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a stack-based buffer overflow in Microsoft Office Access when processing specially crafted data pasted or imported by a user. A remote attacker can provide specially crafted data and convince a user to paste or import it to execute arbitrary code.

The Preview Pane is not an attack vector.


Affected software

Microsoft 365 Apps for Enterprise
Microsoft Access
Microsoft Office

How to mitigate CVE-2026-69614

Install security update from vendor's website.

Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Access - update to 16.0.5569.1002
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976

External References

Related Security Bulletins