ZeroHour

CVE-2026-69360

mass

Heap Buffer Overflow RCE in Microsoft Word

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69360 is a heap-based buffer overflow (CWE-122) in Microsoft Word that allows an unauthorized attacker to execute code over a network. The CVSS vector indicates exploitation requires user interaction (UI:R) with no privileges needed, which is consistent with an attacker persuading a user to open attacker-supplied content such as a crafted document, after which the overflow in Word is triggered. Successful exploitation yields arbitrary code execution in the context of the Word process, typically granting the attacker the privileges of the logged-in user on the victim machine, with high impact to confidentiality, integrity, and availability. Any user or organization running affected Microsoft Word/Office versions is exposed, making the practical attack surface extremely broad. As of this writing there is no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a ~0.8% probability of exploitation within 30 days (53rd percentile).

What to do: Apply the Word/Office security update for CVE-2026-69360 from the Microsoft MSRC advisory as soon as it is deployed through your update channel (Microsoft Update/Office update channel); check with Microsoft for the exact fixed build numbers for your Office version. Until patched, caution users against opening untrusted documents and consider defenses such as Office Attack Surface Reduction rules (e.g., blocking Office applications from creating child processes) and keeping Protected View enabled. Monitor MSRC and CISA KEV for updates, since exploitation status may change.

Affected
Microsoft Word (Microsoft Office)
Estimated exposure
masshundreds of millions of users (Word ships with Microsoft Office/Microsoft 365, which has 400M+ commercial seats and is bundled on most enterprise Windows PCs) — Word is a core component of Microsoft Office/Microsoft 365, whose install base is measured in hundreds of millions of seats and effectively all managed Windows endpoints, so any unpatched Word install is potentially affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.