ZeroHour

CVE-2026-69556

mass

Heap-Based Buffer Overflow in Microsoft Word Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69556 is a heap-based buffer overflow (CWE-122) in Microsoft Word that allows an unauthorized attacker to execute arbitrary code over a network. Exploitation requires delivering a maliciously crafted document or network input to a vulnerable Word installation, with the CVSS user-interaction metric (UI:R) indicating the target must open or process the attacker-supplied content. Successful exploitation yields full confidentiality, integrity, and availability impact per the CVSS vector, meaning the attacker can run code with the privileges of the logged-in user. Users of Word across Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, 2021, and 2024 releases are affected. As of this analysis there is no entry in CISA's KEV catalog, no known public proof-of-concept, and EPSS assigns only a 0.8% probability of exploitation within 30 days, so exploitation is not confirmed.

What to do: Apply Microsoft's security updates for Word/Office (Microsoft 365 Apps, Office 2019, 2021, and 2024) via Microsoft Update as soon as they are available for your channel, and verify the patched build in an Office app under Account > About. Until patched, caution users against opening Word documents from untrusted sources, since exploitation requires user interaction, and consider disabling Office document preview and mark-of-the-web handling exceptions where feasible. Endpoint teams should prioritize internet-connected and mail-exposed workstations given the network attack vector, though no in-the-wild exploitation is currently confirmed.

Affected
microsoft Word
microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Word is bundled with Microsoft 365 and Office perpetual installs across consumer and enterprise desktops) — Word ships with Microsoft 365 — which Microsoft reports at several hundred million paid seats — plus the widely deployed Office 2019/2021/2024 perpetual editions, making the installed base far above the mass threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.