ZeroHour

CVE-2026-69764

mass

Heap-Based Buffer Overflow RCE in Microsoft Word (Office 2016-2024, M365 Apps)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69764 is a heap-based buffer overflow (CWE-122) in Microsoft Word's processing of documents. An attacker triggers it by convincing a user to open a maliciously crafted file: the attack vector is network-based and requires no privileges or credentials, but it does require user interaction, after which the flaw lets the attacker execute arbitrary code in the context of the logged-in user. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8, High). Affected users include anyone running the Word component of Microsoft 365 Apps or the standalone Office 2016, 2019, 2021, and 2024 releases. Exploitation has not yet been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.8% probability of exploitation within 30 days.

What to do: Apply Microsoft's security updates for Word across all affected channels (Microsoft 365 Apps and Office 2016/2019/2021/2024) as published in Microsoft's advisory, prioritizing workstations that regularly open files from external sources, and check the advisory for the exact fixed build for each version. Because exploitation requires a user to open a crafted document, reinforce caution with untrusted email attachments and downloaded files until patches are deployed. No public PoC or in-the-wild exploitation is known, so patching during the regular cycle is reasonable, but high-exposure users (front-office, helpdesk, users of shared file shares) should be patched first.

Affected
Microsoft 365 Apps (Word)
microsoft Office 2016 (Word)
microsoft Office 2019 (Word)
microsoft Office 2021 (Word)
microsoft Office 2024 (Word)
microsoft Word (standalone)
Estimated exposure
masshundreds of millions of users, likely >100M affected installations (order of magnitude 10^8) — Microsoft 365/Office is the dominant desktop productivity suite with hundreds of millions of commercial users and Word present on the vast majority of managed Windows endpoints, so a flaw in Word's document parsing plausibly touches an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2016, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.