CVE-2026-78517
massHeap-Based Buffer Overflow RCE in Microsoft Word (Office 2019/2021/2024/365)
CVE-2026-78517 is a heap-based buffer overflow (CWE-122) in Microsoft Word, the word processor included with Microsoft Office and Microsoft 365 Apps. A remote, unauthenticated attacker can trigger the flaw by getting a user to open attacker-controlled content — the CVSS vector confirms a network attack vector with user interaction required and no privileges needed. Successful exploitation allows the attacker to execute arbitrary code on the victim's system. Affected deployments include Word within Microsoft 365 and Microsoft 365 Apps as well as the perpetual Office 2019, Office 2021, and Office 2024 releases. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is known.
What to do: Apply Microsoft's latest security updates for Word/Office covering Microsoft 365 Apps and Office 2019/2021/2024 on all endpoints, and verify installed channel/build versions against Microsoft's advisory to confirm the fix is deployed. Until patched, caution users against opening untrusted documents and consider email filtering or attachment-sandboxing to reduce exposure. Track the dashboard for updates, as exploitation activity or public PoCs may emerge.
| microsoft Word | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.