ZeroHour

CVE-2026-78517

mass

Heap-Based Buffer Overflow RCE in Microsoft Word (Office 2019/2021/2024/365)

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-78517 is a heap-based buffer overflow (CWE-122) in Microsoft Word, the word processor included with Microsoft Office and Microsoft 365 Apps. A remote, unauthenticated attacker can trigger the flaw by getting a user to open attacker-controlled content — the CVSS vector confirms a network attack vector with user interaction required and no privileges needed. Successful exploitation allows the attacker to execute arbitrary code on the victim's system. Affected deployments include Word within Microsoft 365 and Microsoft 365 Apps as well as the perpetual Office 2019, Office 2021, and Office 2024 releases. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is known.

What to do: Apply Microsoft's latest security updates for Word/Office covering Microsoft 365 Apps and Office 2019/2021/2024 on all endpoints, and verify installed channel/build versions against Microsoft's advisory to confirm the fix is deployed. Until patched, caution users against opening untrusted documents and consider email filtering or attachment-sandboxing to reduce exposure. Track the dashboard for updates, as exploitation activity or public PoCs may emerge.

Affected
microsoft Word
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Microsoft 365 Apps
Microsoft 365
Estimated exposure
mass≈1 billion+ users (global Microsoft Office/Word installed base) — Word ships with Microsoft Office and Microsoft 365, whose worldwide installed base is on the order of a billion users across enterprise and consumer seats, making the potential exposed population very large even though only users opening…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.