ZeroHour

CVE-2026-78521

mass

Heap Buffer Overflow in Microsoft Word Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-78521 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word, a memory-corruption flaw that occurs when the application processes attacker-controlled content. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an attacker needs no privileges or credentials and can deliver a crafted file over a network, such as via email, but a user must interact with it, most plausibly by opening or previewing a malicious Word document. Successful exploitation yields arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected deployments include Word as shipped in Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, 2021, and 2024 releases. The flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS assigns a modest 0.6% probability of exploitation within 30 days, so there is currently no confirmed exploitation in the wild.

What to do: Apply Microsoft's security update addressing CVE-2026-78521 across all Office branches in use (Microsoft 365 Apps, Office 2019/2021/2024), and confirm Microsoft 365 Apps are running the latest channel build after update. Until patched, treat Word documents from untrusted senders as suspect and remind users that opening or previewing a crafted file is the required trigger; no public exploit or workaround details are available in the current data.

Affected
Microsoft Word (component of Office/Microsoft 365)
Microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Word ships with every Office/Microsoft 365 install worldwide) — Microsoft 365 alone has on the order of 400 million commercial seats and Word is bundled with every Office and Microsoft 365 deployment, so even a conservative fraction of unpatched endpoints puts affected users well above 1 million; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.