ZeroHour

CVE-2026-78512

mass

Unauthenticated RCE in Microsoft Word via Numeric Truncation Error

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-78512 is a numeric truncation error (CWE-197) in Microsoft Office Word, in which a numeric value is truncated during processing, associated with a heap-based buffer overflow (CWE-122) that corrupts memory in Word's document handling. Per the CVSS vector (AV:N/AC:L/PR:N/UI:R), a remote, unauthenticated attacker can trigger it over the network, most plausibly by getting a user to open attacker-supplied content such as a crafted Word document received via email or downloaded from the web. Successful exploitation lets the attacker execute arbitrary code in the context of the signed-in user, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score: 8.8, High). All supported Word-bearing releases are affected - Microsoft 365 Apps, Microsoft 365, Office 2016, 2019, 2021, and 2024, plus standalone Word - so effectively every user of a supported Word installation is in scope. There is no evidence of active exploitation yet: no public proof-of-concept, no CISA KEV listing, and EPSS assigns a 0.8% probability of exploitation within 30 days (55th percentile).

What to do: Apply Microsoft's security update for Word covering CVE-2026-78512 as soon as it ships via Microsoft Update and the monthly Patch Tuesday channel, and inventory installed Office builds to confirm patched status. Because exploitation requires user interaction, until systems are patched treat unsolicited Word documents as untrusted and rely on standard Office protections (e.g., Protected View) to limit code execution. For Office 2016/2019 estates, verify they are still in a supported servicing channel and confirm whether an applicable update exists or plan an upgrade path.

Affected
Microsoft 365 Apps (Word)
Microsoft 365
microsoft Office 2016 (Word)
microsoft Office 2019 (Word)
microsoft Office 2021 (Word)
microsoft Office 2024 (Word)
Microsoft Word (standalone)
Estimated exposure
masshundreds of millions of users/devices (all supported Word-bearing Office and Microsoft 365 releases listed as affected) — Word is bundled with essentially every Microsoft Office and Microsoft 365 deployment, and the advisory lists every supported Word-bearing release from Office 2016 through Microsoft 365 Apps as affected, making the potentially affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024, word
Weakness
CWE-122, CWE-197
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.