ZeroHour

CVE-2026-78511

mass

Heap Buffer Overflow in Microsoft Word Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-78511 is a heap-based buffer overflow (CWE-122) in Microsoft Word that can be reached over a network. Triggering it requires user interaction: an attacker must persuade a user to open a maliciously crafted Word document, since the CVSS vector shows UI:R with no privileges required. A successful exploit allows an unauthenticated attacker to execute arbitrary code in the context of the victim user, with high impact on confidentiality, integrity, and availability at that user's privilege level. Affected products include Word as shipped in Microsoft 365/Microsoft 365 Apps and perpetual Office 2019, Office 2021, and Office 2024. There is no confirmed exploitation yet: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.8% chance of exploitation in the next 30 days.

What to do: Apply the patched Word/Office builds listed in Microsoft's security advisory as soon as they are available for your update channel, and confirm Microsoft 365 Apps servicing is current. Until patched, treat unsolicited Word documents (.doc/.docx, including in email) with suspicion and rely on Protected View and attachment-scanning controls as interim mitigation. Monitor KEV and exploit feeds, since a network-reachable Word RCE is likely to draw attacker attention once a PoC appears.

Affected
microsoft Word
Microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
mass≈1 billion users/devices (Word is ubiquitous across Microsoft 365's 400M+ paid seats plus perpetual Office installs) — Estimate based on Microsoft's reported scale of Microsoft 365/Office deployment (hundreds of millions of paid seats and over a billion total Office users), making nearly every enterprise and consumer Windows/Mac endpoint with Word…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.