CVE-2026-69477: Microsoft Office Access Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
Other sources
Microsoft Office Access Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20976 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20138
Event History
Frequently Asked Questions
What access and user interaction are required for exploitation?
The attacker must be authorized with local access and requires user interaction. The provided data does not specify the exact interaction or delivery mechanism.
Which Microsoft Access deployments are listed as affected?
The affected software list includes Access 2016; Microsoft 365 Apps for Enterprise; Office 2019 in 32-bit and 64-bit editions; Office LTSC 2021 in 32-bit and 64-bit editions; and Office LTSC 2024 in 32-bit and 64-bit editions.