Sceawere

Vulnerability Detail

CVE-2026-64912UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Access Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-121: Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:52.440Z",
  "pubdate": "2026-08-11T17:18:52.440Z",
  "executiveSummary": "A stack-based buffer overflow vulnerability has been identified within Microsoft Office Access, posing significant risk to system integrity and user security.\nThis vulnerability allows an unauthorized local attacker to execute arbitrary code within the context of the currently logged-on user.\nThe flaw stems from improper validation of input data length when processing specific structures within Microsoft Office Access, resulting in memory corruption on the stack.\nSuccessful exploitation of this security defect can lead to localized system compromise, unauthorized data access, or application crashes.\nAlthough the attack requires local execution capabilities by an unauthorized threat actor, the severity of potential code execution necessitates prompt remediation through official vendor patches and strict adherence to principle of least privilege access controls.",
  "technicalDetails": "The vulnerability is classified as a stack-based buffer overflow, occurring when Microsoft Office Access processes malformed input without adequately verifying the size bounds of the data being copied into allocated stack memory buffers.\nThe vulnerable component resides within the parsing logic of Microsoft Office Access, specifically handling untrusted file formats or data structures that exceed expected memory allocations.\nWhen an unauthorized local attacker supplies a specially crafted file or input stream designed to trigger the parsing routines, the excessive data overflows the boundaries of the stack-based buffer.\nThis overflow overwrites adjacent stack memory structures, including critical execution control data such as saved frame pointers and return addresses.\nDuring the step-by-step exploitation flow, the instruction pointer (EIP/RIP) is redirected to malicious shellcode injected into the stack by the attacker, contingent upon bypassing modern exploit mitigations if present.\nAuthentication requirements are minimal, as the attack surface is exposed locally to any unauthorized user capable of launching the application with the malicious payload.\nPrivilege requirements are limited to standard local user privileges, meaning the resulting arbitrary code execution inherits the security context of the targeted user running Microsoft Office Access.\nNetwork exposure is not directly applicable for remote exploitation vectors based on the provided parameters, classifying this strictly as a local attack vector.\nPost-exploitation impact includes unauthorized execution of arbitrary commands, escalation of privileges if auxiliary local kernel vulnerabilities exist, deployment of secondary payloads, and persistent compromise of the local user environment."
}
CVE-2026-64912: Microsoft Office Access Buffer Overflow (HIGH Severity, CVSS: 7.8) - Sceawere