Skip to main content

CVE-2026-55017

Microsoft Office Remote Code Execution vulnerability

Microsoft

MSRC advisory July 14, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-55017
Affected products
Microsoft Office Remote Code Execution · Microsoft Microsoft Office Remote Code Execution · Microsoft

What happened

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

What it means for your business

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55017) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

Microsoft MSRC

CVE-2026-69492

Windows Partition Management Driver Elevation of Privilege vulnerability

Windows Partition Management Driver Elevation of Privilege vulnerability (CVE-2026-69492) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62693

Windows MIDI Service Module Elevation of Privileges vulnerability

Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-62693) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45499

Azure OpenAI Elevation of Privilege vulnerability

Azure OpenAI Elevation of Privilege vulnerability (CVE-2026-45499) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85880). Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. CISA remediation due date: 2026-09-22. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.