CVE-2026-72972
massHeap-Based Buffer Overflow in Microsoft Word Allows Remote Code Execution
Microsoft Word contains a heap-based buffer overflow (CWE-122) that an unauthorized attacker can exploit to execute code over a network, per Microsoft's advisory. Exploitation requires user interaction (CVSS UI:R), most plausibly opening or previewing a specially crafted Word document, after which the attacker runs arbitrary code with the privileges of the logged-in user. The flaw is rated 8.8 (high) on CVSS 3.1 with high impact to confidentiality, integrity, and availability. It affects Word in Microsoft 365 Apps and in perpetual editions Office 2019, Office 2021, and Office 2024. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at only 0.8%, so there is no confirmed exploitation to date.
What to do: Apply Microsoft's security update for CVE-2026-72972 as soon as it is released, updating all editions in scope (Office 2019, 2021, 2024, and Microsoft 365 Apps) to the latest patched builds and confirming current versions via File > Account in any Office app. Until patched, warn users not to open Word documents from untrusted sources, since user interaction is required for exploitation, and rely on Protected View and mark-of-the-web defenses. Check Microsoft's release notes for the fixed build numbers, as specific patched versions are not included in the available data.
| Microsoft 365 Apps (including Word) | — |
| Microsoft 365 (including Word) | — |
| microsoft Office 2019 (including Word) | — |
| microsoft Office 2021 (including Word) | — |
| microsoft Office 2024 (including Word) | — |
| microsoft Word | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.