CVE-2026-42831

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:office:2024:*:*:*:ltsc:macos:*:*
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*

History

22 May 2026, 14:49

Type Values Removed Values Added
First Time Microsoft 365 Copilot
CPE cpe:2.3:a:microsoft:office:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*

19 May 2026, 18:38

Type Values Removed Values Added
First Time Microsoft office Long Term Servicing Channel
CPE cpe:2.3:a:microsoft:office:2021:*:*:*:ltsc:macos:*:* cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*

16 May 2026, 02:05

Type Values Removed Values Added
First Time Microsoft
Microsoft office
CPE cpe:2.3:a:microsoft:office:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:office:2021:*:*:*:ltsc:macos:*:*
cpe:2.3:a:microsoft:office:2024:*:*:*:ltsc:macos:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831 - Vendor Advisory

12 May 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 18:17

Updated : 2026-05-22 14:49


NVD link : CVE-2026-42831

Mitre link : CVE-2026-42831

CVE.ORG link : CVE-2026-42831


JSON object : View

Products Affected

microsoft

  • 365_copilot
  • office
  • office_long_term_servicing_channel
CWE
CWE-122

Heap-based Buffer Overflow