CVE-2026-69632: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20976 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20207
Event History
Frequently Asked Questions
Does an attacker need prior access or elevated privileges to exploit this issue?
No prior privileges are required. The vector indicates network-based exploitation with low attack complexity, but user interaction is required.
Which Microsoft Office deployments are listed as affected?
Affected software includes Microsoft 365 Apps for Enterprise; Office 2019 32-bit; Office LTSC 2021 for 32-bit and 64-bit editions; Office LTSC 2024 for 32-bit and 64-bit editions; and Office LTSC for Mac 2021 and 2024.
What could successful exploitation allow?
Successful exploitation could enable code execution and has high-rated impacts on confidentiality, integrity, and availability.