CVE-2026-78525
massUse-After-Free RCE in Microsoft Office (Outlook, Word, Office Suites)
CVE-2026-78525 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Outlook that an unauthorized attacker can trigger over a network, per Microsoft's advisory; the CPE data also lists Word and the Office suites (2019, 2021, 2024, Microsoft 365 Apps), suggesting the vulnerable code affects shared Office components beyond Outlook alone. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an attacker needs no privileges or special conditions but must get a user to interact, most plausibly by having them open crafted email content or a malicious document. Successful exploitation yields arbitrary code execution running with the victim's privileges, with high impact on confidentiality, integrity, and availability. Anyone running the affected Office/Outlook releases is potentially affected, with risk concentrated in environments where users routinely open email attachments or linked content. There is currently no public proof of concept, no CISA KEV listing, and EPSS assigns a modest 0.8% probability of exploitation within 30 days, so no active exploitation is confirmed.
What to do: Apply Microsoft's security update for the affected Office/Outlook builds as soon as it is available, prioritizing mail-reviewer and helpdesk workstations that open untrusted email and documents; check Microsoft's advisory for the exact fixed build numbers for each Office version since they are not listed in this data. In the interim, caution users against opening attachments or embedded content from unknown senders, and confirm remediation by verifying Outlook/Word build numbers against the advisory. No workarounds are specified in the source data.
| Microsoft Office Outlook | — |
| Microsoft Word | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
| Microsoft 365 Apps | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.