ZeroHour

CVE-2026-77504

mass

Double-Free Memory Corruption RCE in Microsoft Office Word

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-77504 is a double-free vulnerability (CWE-415) in Microsoft Office Word, a memory-safety bug in which the same allocated resource is freed twice, corrupting process memory. The CVSS vector indicates it can be reached over a network by an unauthorized attacker with no privileges or special conditions, but user interaction is required, which is consistent with the victim opening or interacting with attacker-supplied Word content. Successful exploitation allows the attacker to execute arbitrary code on the user's system, with high impact on confidentiality, integrity, and availability. All users of affected Microsoft Word/Office builds are potentially exposed; the source data does not specify exact affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.6% (roughly median) probability of exploitation within 30 days, indicating no known in-the-wild exploitation yet.

What to do: Track the Microsoft Security Response Center advisory for CVE-2026-77504 and deploy the corresponding Word/Office security update as soon as it is released, prioritizing users who routinely open untrusted documents. Check installed Word builds (File > Account > About Word in Word) and verify they are covered by the fix; as an interim measure, instruct users to avoid opening Word documents from untrusted sources and consider protected view or Attack Surface Reduction rules. With no known PoC or in-the-wild exploitation, routine patch-cadence handling is reasonable, but the 8.8 CVSS justifies including this in the next patch cycle.

Affected
Microsoft Office Word (Microsoft Word)
Estimated exposure
masson the order of hundreds of millions of users (Word is a core component of Microsoft Office/Microsoft 365, deployed broadly across enterprises and consumer… — Word ships with the Microsoft Office and Microsoft 365 suites, which are used by hundreds of millions of users worldwide, so essentially every managed desktop estate is within the blast radius even though exploitability requires user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.