CVE-2026-69614: Microsoft Office Access Remote Code Execution Vulnerability
Microsoft Office Access Remote Code Execution Vulnerability
Other sources
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1002Patch KB5002912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20976
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The affected software list includes Microsoft 365 Apps for Enterprise; Microsoft Access 2016; Office 2019 for 32-bit and 64-bit editions; Office LTSC 2021 for 32-bit and 64-bit editions; and Office LTSC 2024 for 32-bit and 64-bit editions.
Does exploitation require authentication or user interaction?
The CVSS vector indicates that no privileges are required, but user interaction is required. It also indicates network attack vector and low attack complexity.
What could a successful exploit allow?
A successful exploit could allow code execution. The supplied CVSS metrics rate confidentiality, integrity, and availability impact as high.
Are temporary mitigations or detection methods provided?
The supplied data does not provide a workaround, mitigation, or method for determining whether exploitation has occurred.