ZeroHour

CVE-2026-78514

mass

Use-After-Free Remote Code Execution in Microsoft Word

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-78514 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Word that allows an unauthorized attacker to execute arbitrary code over a network. Based on the CVSS vector (network attack vector, low complexity, no privileges required, but user interaction required), exploitation likely requires convincing a user to open attacker-controlled content, such as a crafted document. A successful exploit grants the attacker code execution in the context of the user, with high impact on confidentiality, integrity, and availability. Users of Word across Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024 are affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating a 0.6% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-78514 as soon as it is available via Microsoft Update/Windows Update or your patch management system, prioritizing workstations where users open untrusted documents. Until patched, rely on email filtering and user caution with attachments, and consider Office Protected View and Attack Surface Reduction rules (e.g., blocking Office applications from creating child processes) to limit exploitation impact. Check your environment for the affected Word/Office editions listed above and verify post-patch build numbers against Microsoft's advisory.

Affected
microsoft word
microsoft 365 apps
microsoft 365
microsoft office 2019
microsoft office 2021
microsoft office 2024
Estimated exposure
masshundreds of millions of users (Word is bundled with Microsoft 365 and perpetually licensed Office suites) — Word ships with Microsoft 365 and Office, whose combined commercial and consumer installed base is on the order of hundreds of millions of seats, so essentially every organization or individual running any supported Word version is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.