CVE-2026-78507
massUse-After-Free RCE in Microsoft Word (Office 2019-2024, Microsoft 365 Apps)
CVE-2026-78507 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft Word, rated High (CVSS 3.1: 8.8), that Microsoft says allows an unauthorized attacker to execute code over a network. The bug is triggered when Word processes maliciously crafted content that frees a memory object while it is still in use; per the CVSS vector, user interaction is required (UI:R), consistent with a user opening or previewing a crafted document, and no privileges are needed beforehand. Successful exploitation yields arbitrary code execution with the privileges of the logged-in user, with high impact on confidentiality, integrity, and availability on the victim machine. Affected deployments include Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024, though specific affected and fixed build numbers are not provided in the available data. As of now there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.6% probability of exploitation within 30 days, so no exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-78507 as soon as it is available and confirm the exact fixed build numbers in Microsoft's advisory, since they are not listed in this data; inventory deployed versions (e.g., via Word > Account > About Word for Click-to-Run build numbers) across Microsoft 365 Apps and Office 2019/2021/2024 installations and verify the Office 2019 support path if still deployed. Until patched, caution users against opening or previewing documents from untrusted sources, since exploitation requires user interaction.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| Microsoft Office 2019 (Word) | — |
| Microsoft Office 2021 (Word) | — |
| Microsoft Office 2024 (Word) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.