ZeroHour

CVE-2026-72973

mass

Heap Buffer Overflow in Microsoft Word Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-72973 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that Microsoft says an unauthorized attacker can exploit over a network to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attack does not require privileges or authentication but does require user interaction, most likely the victim opening a maliciously crafted document or file handled by Word. Successful exploitation yields remote code execution in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. Anyone running Word as part of Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, Office 2021, and Office 2024 suites is affected. There is currently no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.8% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-72973 to Word across all listed Office channels as soon as it is published, prioritizing endpoints and users who routinely open untrusted documents (verify installed builds via File > Account in any Office app). Until patching is complete, warn users not to open unsolicited or untrusted documents and consider disabling the Outlook preview pane, which can auto-open Word content. Because the source data does not include affected build numbers, confirm the exact version ranges in Microsoft's advisory before scoping remediation.

Affected
microsoft Word (Microsoft Word application)
Microsoft 365 Apps (Word component)
Microsoft 365 (Word component)
microsoft Office 2019 (Word component)
microsoft Office 2021 (Word component)
microsoft Office 2024 (Word component)
Estimated exposure
masshundreds of millions of users/installations (Word ships with all Microsoft 365 and Office deployments) — Word is bundled with Microsoft 365 and Office suites, whose combined commercial and consumer installed base is measured in hundreds of millions of seats and devices worldwide, so essentially every unpatched Word installation is exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.