CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Patch KB5002878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20131.20024
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45474?
The severity of CVE-2026-45474 is rated high with a score of 8.4.
What is CVE-2026-45474?
CVE-2026-45474 is a Microsoft Office Remote Code Execution Vulnerability caused by a heap-based buffer overflow.
How do I fix CVE-2026-45474?
To fix CVE-2026-45474, apply the latest security updates provided by Microsoft for affected Office products.
Which versions of Microsoft Office are affected by CVE-2026-45474?
CVE-2026-45474 affects Microsoft Office 2016, Microsoft 365 Apps for Enterprise, and several other Microsoft Office versions and editions.
What impact does CVE-2026-45474 have on system security?
CVE-2026-45474 allows an unauthorized attacker to execute code locally, posing a significant threat to system integrity and confidentiality.