CVE-2026-78511
massHeap Buffer Overflow in Microsoft Word Allows Remote Code Execution
CVE-2026-78511 is a heap-based buffer overflow (CWE-122) in Microsoft Word that can be reached over a network. Triggering it requires user interaction: an attacker must persuade a user to open a maliciously crafted Word document, since the CVSS vector shows UI:R with no privileges required. A successful exploit allows an unauthenticated attacker to execute arbitrary code in the context of the victim user, with high impact on confidentiality, integrity, and availability at that user's privilege level. Affected products include Word as shipped in Microsoft 365/Microsoft 365 Apps and perpetual Office 2019, Office 2021, and Office 2024. There is no confirmed exploitation yet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.8% chance of exploitation in the next 30 days.
What to do: Apply the patched Word/Office builds listed in Microsoft's security advisory as soon as they are available for your update channel, and confirm Microsoft 365 Apps servicing is current. Until patched, treat unsolicited Word documents (.doc/.docx, including in email) with suspicion and rely on Protected View and attachment-scanning controls as interim mitigation. Monitor KEV and exploit feeds, since a network-reachable Word RCE is likely to draw attacker attention once a PoC appears.
| microsoft Word | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.