CVE-2026-55056: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1000Patch KB5002887 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is rated with local attack vector and no privileges required. Exploitation requires user interaction, so an attacker would need to induce a user to interact with malicious content locally.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow code execution with high impacts to confidentiality, integrity, and availability. The affected component is Microsoft Office.
Which Office products should be included in remediation scoping?
The listed affected products are Office 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps, Microsoft 365 Apps for Enterprise, Office LTSC 2024 for 64-bit editions, and Office 365 for Mac.