CVE-2026-69556
massHeap-Based Buffer Overflow in Microsoft Word Enables Remote Code Execution
CVE-2026-69556 is a heap-based buffer overflow (CWE-122) in Microsoft Word that allows an unauthorized attacker to execute arbitrary code over a network. Exploitation requires delivering a maliciously crafted document or network input to a vulnerable Word installation, with the CVSS user-interaction metric (UI:R) indicating the target must open or process the attacker-supplied content. Successful exploitation yields full confidentiality, integrity, and availability impact per the CVSS vector, meaning the attacker can run code with the privileges of the logged-in user. Users of Word across Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, 2021, and 2024 releases are affected. As of this analysis there is no entry in CISA's KEV catalog, no known public proof-of-concept, and EPSS assigns only a 0.8% probability of exploitation within 30 days, so exploitation is not confirmed.
What to do: Apply Microsoft's security updates for Word/Office (Microsoft 365 Apps, Office 2019, 2021, and 2024) via Microsoft Update as soon as they are available for your channel, and verify the patched build in an Office app under Account > About. Until patched, caution users against opening Word documents from untrusted sources, since exploitation requires user interaction, and consider disabling Office document preview and mark-of-the-web handling exceptions where feasible. Endpoint teams should prioritize internet-connected and mail-exposed workstations given the network attack vector, though no in-the-wild exploitation is currently confirmed.
| microsoft Word | — |
| microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.