CVE-2026-77504
massDouble-Free Memory Corruption RCE in Microsoft Office Word
CVE-2026-77504 is a double-free vulnerability (CWE-415) in Microsoft Office Word, a memory-safety bug in which the same allocated resource is freed twice, corrupting process memory. The CVSS vector indicates it can be reached over a network by an unauthorized attacker with no privileges or special conditions, but user interaction is required, which is consistent with the victim opening or interacting with attacker-supplied Word content. Successful exploitation allows the attacker to execute arbitrary code on the user's system, with high impact on confidentiality, integrity, and availability. All users of affected Microsoft Word/Office builds are potentially exposed; the source data does not specify exact affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.6% (roughly median) probability of exploitation within 30 days, indicating no known in-the-wild exploitation yet.
What to do: Track the Microsoft Security Response Center advisory for CVE-2026-77504 and deploy the corresponding Word/Office security update as soon as it is released, prioritizing users who routinely open untrusted documents. Check installed Word builds (File > Account > About Word in Word) and verify they are covered by the fix; as an interim measure, instruct users to avoid opening Word documents from untrusted sources and consider protected view or Attack Surface Reduction rules. With no known PoC or in-the-wild exploitation, routine patch-cadence handling is reasonable, but the 8.8 CVSS justifies including this in the next patch cycle.
| Microsoft Office Word (Microsoft Word) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.