CVE-2026-44824: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Patch KB5002878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881
Event History
Frequently Asked Questions
What is CVE-2026-44824?
CVE-2026-44824 is a vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally due to a heap-based buffer overflow.
What is the severity level of CVE-2026-44824?
The severity level of CVE-2026-44824 is high with a score of 7.8.
How can I mitigate CVE-2026-44824?
To mitigate CVE-2026-44824, it is recommended to update Microsoft Office and other affected software to the latest security patches provided by Microsoft.
What systems are affected by CVE-2026-44824?
CVE-2026-44824 affects Microsoft Office 2016, Microsoft SharePoint Server, Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office LTSC for Mac 2024.
What are the potential impacts of exploiting CVE-2026-44824?
Exploiting CVE-2026-44824 could allow an attacker to execute arbitrary code, leading to potential unauthorized access to sensitive data or system control.