CVE-2026-55133: Microsoft OneNote Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
Other sources
Microsoft OneNote Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.111.26071215
Event History
Frequently Asked Questions
What must an attacker have or do to exploit this issue?
The attack vector is local, no privileges are required, and user interaction is required. The available data does not identify the specific interaction or delivery method.
Which environments should be prioritized for assessment?
Prioritize systems running Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office LTSC for Mac 2024 or 2021, Microsoft Office 365 for Mac, Microsoft 365 macOS, Microsoft Office 2021 macOS, or Microsoft Office 2024 macOS.
What is the potential security impact after successful exploitation?
Successful exploitation can result in local code execution. The supplied severity vector rates confidentiality, integrity, and availability impact as high.