ZeroHour

CVE-2026-62804

mass

External file path control allows local code execution in Microsoft Word

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-62804 is an external control of file name or path flaw (CWE-73) in Microsoft Word, meaning Word constructs a file path from input an attacker controls without sufficient validation. Because the attack vector is local and user interaction is required (CVSS vector AV:L/UI:R), an attacker must deliver a crafted file or path, such as via a malicious document or downloaded file, and persuade a local user to open or act on it. Successful exploitation lets an unauthorized attacker execute code locally in the user's context, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, high). Anyone running Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2016, 2019, 2021, or 2024 releases with the affected Word component is exposed. As of the provided data the flaw is not in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days, so there is no evidence of active exploitation yet.

What to do: Apply the Word security update Microsoft releases for this CVE as soon as it is available through your normal channels (Microsoft 365 Apps update channel, or Microsoft Update/WSUS for perpetual Office 2016-2024), and verify installed Office builds against Microsoft's advisory once patched version numbers are published. Until patched, treat unsolicited documents and downloaded files as the likely trigger vector and remind users not to open untrusted files, since exploitation requires local user interaction.

Affected
Microsoft 365 Apps
Microsoft 365
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of users/installs (Microsoft 365 alone has 400M+ paid seats and perpetual Office 2016-2024 remain widespread) — Word ships with Microsoft 365 and perpetual Office on effectively every managed Windows endpoint and many consumer devices, and Microsoft 365 is publicly reported at over 400 million paid seats, so the plausible exposed population is on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-73
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.