ZeroHour

CVE-2026-77901

mass

Null Pointer Dereference RCE in Microsoft Word (Office 2019–2024, Microsoft 365)

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-77901 is a NULL pointer dereference (CWE-476) in the Microsoft Word component of Office that Microsoft classifies as a flaw allowing an unauthenticated attacker to execute code over a network, with a CVSS 3.1 base score of 8.8. The attack path is network-delivered but requires user interaction (AV:N/PR:N/UI:R), meaning an attacker typically needs to get a user to open a maliciously crafted document that causes Word to dereference a null pointer. Successful exploitation would give the attacker code execution on the victim's machine in the user's context, with high impact to confidentiality, integrity and availability (C:H/I:H/A:H). Anyone running Word within Office 2019, Office 2021, Office 2024, Microsoft 365 or Microsoft 365 Apps is in scope. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and EPSS estimates only about a 0.6% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Inventory your estate for Word within Office 2019, 2021, 2024, Microsoft 365 and Microsoft 365 Apps, and apply Microsoft's Word/Office security update for CVE-2026-77901 as soon as it is available (fixed build numbers are not listed in the available data; Microsoft 365 Apps normally receives fixes via its regular update channel). Until patching, keep Office Protected View enabled and treat unsolicited or untrusted Word documents with suspicion, since user interaction with a crafted document is the likely trigger. No workarounds are confirmed in the available data, so verify any mitigation guidance against Microsoft's advisory.

Affected
Microsoft Word
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Microsoft 365
Microsoft 365 Apps
Estimated exposure
mass≈1 billion+ Word installations / hundreds of millions of users (Word ships with ubiquitous Office and Microsoft 365 deployments) — Estimate based on Word's ubiquity: it is bundled with essentially all Office suites and Microsoft 365 subscriptions, which are publicly reported as installed on the order of a billion devices and used by hundreds of millions of Microsoft…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.