ZeroHour

CVE-2026-78504

mass

Stack-Based Buffer Overflow RCE in Microsoft Word (Office 2019–2024, Microsoft 365)

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-78504 is a stack-based buffer overflow (CWE-121) in Microsoft Word, the word-processing component bundled with Microsoft 365 Apps/Microsoft 365 and Office 2019, 2021, and 2024, which allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attack requires no authentication or privileges but does require user interaction, most likely a user opening or previewing crafted content processed by Word. A successful exploit would let the attacker run arbitrary code in the context of the user opening the content, with high impact on confidentiality, integrity, and availability of that system. All users of the affected Office editions are potentially exposed, since Word is a core component of each. As of this writing the flaw is not in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.6% probability of exploitation within 30 days.

What to do: Check Microsoft's advisory for CVE-2026-78504 for the affected and fixed Word/Office build numbers (not included in this data) and deploy the corresponding security update via Microsoft Update as soon as it is available. Until patched, discourage opening or previewing Word documents from untrusted sources, and inventory endpoints running Office 2019/2021/2024 and Microsoft 365 Apps so patch progress can be tracked and high-risk users prioritized.

Affected
Microsoft Word (vulnerable component)
Microsoft 365 Apps
Microsoft 365
Microsoft Office 2019 (Word component)
Microsoft Office 2021 (Word component)
Microsoft Office 2024 (Word component)
Estimated exposure
mass≈1 billion+ users (Word ships in every listed Office edition) — Microsoft 365 Apps and Office 2019–2024 are Microsoft's mainstream desktop Office editions, with a combined installed base widely estimated in the hundreds of millions of seats to over a billion users, so plausible exposure is of mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.