ZeroHour

CVE-2026-69671

mass

Heap-Based Buffer Overflow RCE in Microsoft Word (Microsoft 365 and Office suites)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69671 is a heap-based buffer overflow (CWE-122) in Microsoft Word, the word-processing component of Microsoft 365 Apps, Microsoft 365, and the Office 2019, 2021, and 2024 suites. Per the CVSS vector, a remote, unauthenticated attacker can reach the flaw over a network but must induce user interaction, which in practice means corrupting Word's memory when a victim opens attacker-supplied content such as a crafted document. Successful exploitation yields arbitrary code execution in the context of the user running Word, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8, High). Any user or organization running the affected Word/Office editions is exposed; the available data does not specify affected build or version ranges, so consult Microsoft's advisory for details. Exploitation has not yet been observed: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS currently assigns a 0.8% probability of exploitation within 30 days (55th percentile).

What to do: Apply the Microsoft security update for CVE-2026-69671 to all affected Office installations as soon as it is available through your update channel (Windows Update/Microsoft AutoUpdate or the Microsoft Update Catalog), and verify installed Word builds against Microsoft's advisory, since affected version ranges were not specified in the available data. Until patched, discourage opening untrusted documents and consider hardening such as disabling the Outlook/Explorer preview pane and filtering risky attachment types. Given the 8.8 severity and network-reachable code execution, treat this as a high-priority patch even though no in-the-wild exploitation or public PoC is currently known.

Affected
Microsoft 365 Apps (Word component)
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
microsoft Word
Estimated exposure
masshundreds of millions of users (Word ships in Microsoft 365, which has 400M+ paid seats, plus large perpetual Office 2019/2021/2024 install bases) — Microsoft's publicly reported Microsoft 365 subscriber counts (hundreds of millions of seats) and the ubiquity of desktop Office/Word on enterprise and consumer Windows machines make this one of the largest affected software bases of any…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.