Heap-based buffer overflow in Microsoft products - CVE-2026-78509

 

Heap-based buffer overflow in Microsoft products - CVE-2026-78509

Published: September 9, 2026


Vulnerability identifier: #VU148227
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78509
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Outlook when processing a specially crafted email message. A remote attacker can send a specially crafted email message to execute arbitrary code.

Viewing the message in the Outlook Reading Pane can trigger the vulnerability without the recipient opening the message or clicking anything in it.


Affected software

Microsoft Word
Microsoft 365 Apps for Enterprise
Microsoft Office

How to mitigate CVE-2026-78509

Install security update from vendor's website.

Microsoft Word - update to 16.0.5569.1000
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976

External References

Related Security Bulletins