CVE-2026-72973
massHeap Buffer Overflow in Microsoft Word Allows Remote Code Execution
CVE-2026-72973 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that Microsoft says an unauthorized attacker can exploit over a network to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attack does not require privileges or authentication but does require user interaction, most likely the victim opening a maliciously crafted document or file handled by Word. Successful exploitation yields remote code execution in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. Anyone running Word as part of Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, Office 2021, and Office 2024 suites is affected. There is currently no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.8% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-72973 to Word across all listed Office channels as soon as it is published, prioritizing endpoints and users who routinely open untrusted documents (verify installed builds via File > Account in any Office app). Until patching is complete, warn users not to open unsolicited or untrusted documents and consider disabling the Outlook preview pane, which can auto-open Word content. Because the source data does not include affected build numbers, confirm the exact version ranges in Microsoft's advisory before scoping remediation.
| microsoft Word (Microsoft Word application) | — |
| Microsoft 365 Apps (Word component) | — |
| Microsoft 365 (Word component) | — |
| microsoft Office 2019 (Word component) | — |
| microsoft Office 2021 (Word component) | — |
| microsoft Office 2024 (Word component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.