ZeroHour

CVE-2026-72972

mass

Heap-Based Buffer Overflow in Microsoft Word Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

Microsoft Word contains a heap-based buffer overflow (CWE-122) that an unauthorized attacker can exploit to execute code over a network, per Microsoft's advisory. Exploitation requires user interaction (CVSS UI:R), most plausibly opening or previewing a specially crafted Word document, after which the attacker runs arbitrary code with the privileges of the logged-in user. The flaw is rated 8.8 (high) on CVSS 3.1 with high impact to confidentiality, integrity, and availability. It affects Word in Microsoft 365 Apps and in perpetual editions Office 2019, Office 2021, and Office 2024. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at only 0.8%, so there is no confirmed exploitation to date.

What to do: Apply Microsoft's security update for CVE-2026-72972 as soon as it is released, updating all editions in scope (Office 2019, 2021, 2024, and Microsoft 365 Apps) to the latest patched builds and confirming current versions via File > Account in any Office app. Until patched, warn users not to open Word documents from untrusted sources, since user interaction is required for exploitation, and rely on Protected View and mark-of-the-web defenses. Check Microsoft's release notes for the fixed build numbers, as specific patched versions are not included in the available data.

Affected
Microsoft 365 Apps (including Word)
Microsoft 365 (including Word)
microsoft Office 2019 (including Word)
microsoft Office 2021 (including Word)
microsoft Office 2024 (including Word)
microsoft Word
Estimated exposure
masshundreds of millions of users/devices (Word ships in the dominant Office productivity suite) — Microsoft 365 has hundreds of millions of subscribers and perpetual Office editions are deployed on the large majority of enterprise and consumer desktops, so effectively all unpatched Word installations are in scope; this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.