CVE-2026-45475: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Patch KB5002878 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45475?
CVE-2026-45475 has a severity rating of 7.8, classified as high.
How do I fix CVE-2026-45475?
To mitigate CVE-2026-45475, ensure that you apply the latest updates and patches from Microsoft for affected Microsoft Office products.
What type of vulnerability is CVE-2026-45475?
CVE-2026-45475 is a heap-based buffer overflow vulnerability found in Microsoft Office.
Which software is affected by CVE-2026-45475?
CVE-2026-45475 affects Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, and Microsoft SharePoint Server Subscription Edition.
What can an attacker do with CVE-2026-45475?
An unauthorized attacker can exploit CVE-2026-45475 to execute code locally on a vulnerable system.