ZeroHour

CVE-2026-69722

mass

Stack-based buffer overflow in Microsoft Word enables remote code execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69722 is a stack-based buffer overflow (CWE-121) in the Word component of Microsoft Office that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N, PR:N, UI:R) indicates the attack requires no authentication or special privileges but does require user interaction, consistent with an attacker persuading a user to open a maliciously crafted Word document; the exact trigger is not detailed in the available data. Successful exploitation would yield code execution in the context of the user running Word, with high impact on confidentiality, integrity, and availability. Affected products include Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2019, 2021, and 2024 suites, meaning effectively any supported Office installation containing Word is exposed; specific build ranges were not provided in the source data. As of this analysis there is no known in-the-wild exploitation, no CISA KEV listing, and no public proof-of-concept, with EPSS estimating a 0.8% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69722 to Word in all affected products (Microsoft 365 Apps, Office 2019, 2021, and 2024) via the Office/Microsoft 365 update channel as soon as it is available, and verify the patched build under File > Account > About Word. Until patched, avoid opening Word documents from untrusted or unexpected sources and prioritize patching internet-reachable or high-privilege endpoints. Monitor Microsoft's advisory, since no public PoC or in-the-wild exploitation is known yet but the flaw carries high impact if exploited.

Affected
Microsoft 365 Apps
Microsoft 365 (Office)
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Microsoft Word
Estimated exposure
mass~hundreds of millions of users worldwide — Microsoft 365 alone has hundreds of millions of paid seats and the Office 2019/2021/2024 perpetual releases are widely deployed in enterprises, and Word is included in all of these products, so exposure is plausibly on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.

CVE-2026-69722: Stack-based buffer overflow in Microsoft Word enables remote code execution · ZeroHour