CVE-2025-26630: Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5491.1001Patch KB5002697
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-26630?
CVE-2025-26630 is classified as a critical vulnerability that allows for remote code execution in Microsoft Office Access.
How do I fix CVE-2025-26630?
To fix CVE-2025-26630, apply the latest security updates provided by Microsoft for the affected software.
Which software is affected by CVE-2025-26630?
CVE-2025-26630 affects Microsoft Access 2016, Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC versions.
What type of attack does CVE-2025-26630 facilitate?
CVE-2025-26630 facilitates local code execution by an unauthorized attacker through a use-after-free vulnerability.
Is there a specific patch for CVE-2025-26630?
Yes, Microsoft has released specific patches to remediate CVE-2025-26630 which can be found on their update guide.