ZeroHour

CVE-2026-78524

mass

Out-of-bounds write RCE in Microsoft Office and Microsoft 365 Apps

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-78524 is an out-of-bounds write (CWE-787) in Microsoft Office that allows an unauthorized attacker to execute code over a network. The attack path is network-reachable, but per the CVSS vector (UI:R) it requires user interaction, consistent with a victim's Office client processing attacker-supplied content such as a crafted file; no prior privileges are required. Successful exploitation yields code execution in the context of the Office application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Users and organizations running Microsoft 365 Apps, Microsoft 365, or Office 2016/2019/2021/2024 are affected; the source data does not include specific affected or fixed build numbers, so defenders should consult Microsoft's advisory for exact versions. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.8% probability of exploitation within 30 days (56th percentile), indicating no confirmed in-the-wild exploitation yet.

What to do: Prioritize applying the Office security updates published in Microsoft's advisory, focusing first on endpoints that routinely open documents from untrusted sources, and verify installed Microsoft 365 Apps/Office builds against the advisory's fixed versions (not included in this dataset). Until patched, reinforce handling of Office files from unknown origins — treat unexpected attachments and downloaded documents with suspicion and keep active content/macro policies restricted. Monitor Microsoft's advisory and your threat-intel feeds for a public PoC or KEV listing, which would raise patch urgency.

Affected
microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
mass≈hundreds of millions of users and devices — Microsoft 365/Office is the dominant office productivity suite, with Microsoft 365 commercial seats reported in the hundreds of millions and perpetual Office 2016–2024 installs common across enterprise and consumer Windows PCs, so nearly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.