CVE-2026-55033
Analyzed Analyzed - Analysis Complete

Microsoft Word Integer Overflow Code Execution

Vulnerability report for CVE-2026-55033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft word 2016
microsoft word 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55033 is an integer overflow or wraparound vulnerability in Microsoft Office Word. This type of vulnerability occurs when an arithmetic operation attempts to create a numeric value that exceeds the maximum limit of the data type used to store it, leading to unexpected behavior.

In this case, the vulnerability allows an unauthorized attacker to execute arbitrary code locally on the affected system. The attacker could exploit this flaw by crafting a malicious document and tricking a user into opening it, which could then trigger the integer overflow and lead to code execution.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-55033 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office Word or using security tools that can identify known vulnerabilities in installed software.

For Microsoft Office vulnerabilities, you may use built-in tools like Microsoft Update or third-party vulnerability scanners to check for outdated or unpatched software. However, no explicit commands or detection steps are mentioned in the available resources.

Impact Analysis

If you are using a vulnerable version of Microsoft Office Word, this vulnerability could have several impacts:

  • An attacker could execute malicious code on your system, potentially gaining control over it.
  • Sensitive data stored on your system could be accessed, modified, or stolen.
  • The attacker could install malware, spyware, or other harmful software without your knowledge.
  • Your system could be used as a launchpad for further attacks on other systems in your network.

The CVSS base score of 7.8 indicates a high severity, meaning the vulnerability poses a significant risk if exploited.

Compliance Impact

This vulnerability could impact compliance with several common standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): If the vulnerability leads to unauthorized access or disclosure of personal data, it could result in a violation of GDPR. Organizations may face significant fines and reputational damage if they fail to protect personal data adequately.
  • HIPAA (Health Insurance Portability and Accountability Act): For organizations handling protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access to PHI, resulting in non-compliance with HIPAA. This could trigger penalties and mandatory corrective actions.
  • Other standards like ISO 27001, NIST, or PCI DSS: Failure to mitigate this vulnerability could indicate inadequate security controls, leading to non-compliance with these frameworks. This might result in failed audits, loss of certifications, or increased scrutiny from regulators.

Organizations should apply the necessary patches or mitigations promptly to avoid potential compliance violations and associated risks.

Mitigation Strategies

To mitigate CVE-2026-55033, apply the official security update provided by Microsoft as soon as possible. The update addresses the integer overflow or wraparound issue in Microsoft Office Word.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-55033 to download and install the patch.
  • Ensure all systems running Microsoft Office Word are updated to the latest version.
  • If immediate patching is not possible, consider restricting access to Microsoft Office Word or implementing network-level protections to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55033. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart