CVE-2026-55125: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Other sources
Microsoft Office Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55125?
CVE-2026-55125 has a severity rating of 7.8 on the CVSS scale, indicating it is a high severity vulnerability.
What type of vulnerability is CVE-2026-55125?
CVE-2026-55125 is a heap-based buffer overflow vulnerability in Microsoft Office that allows remote code execution.
How do I fix CVE-2026-55125?
To fix CVE-2026-55125, apply the available patches provided by Microsoft for the affected software.
Which software is affected by CVE-2026-55125?
CVE-2026-55125 affects Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft 365 Apps, Microsoft 365 Apps for Enterprise, and Microsoft SharePoint Server.
What could an attacker achieve by exploiting CVE-2026-55125?
An attacker exploiting CVE-2026-55125 could execute arbitrary code on the vulnerable Microsoft Office application locally.