ZeroHour

CVE-2026-78525

mass

Use-After-Free RCE in Microsoft Office (Outlook, Word, Office Suites)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-78525 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Outlook that an unauthorized attacker can trigger over a network, per Microsoft's advisory; the CPE data also lists Word and the Office suites (2019, 2021, 2024, Microsoft 365 Apps), suggesting the vulnerable code affects shared Office components beyond Outlook alone. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an attacker needs no privileges or special conditions but must get a user to interact, most plausibly by having them open crafted email content or a malicious document. Successful exploitation yields arbitrary code execution running with the victim's privileges, with high impact on confidentiality, integrity, and availability. Anyone running the affected Office/Outlook releases is potentially affected, with risk concentrated in environments where users routinely open email attachments or linked content. There is currently no public proof of concept, no CISA KEV listing, and EPSS assigns a modest 0.8% probability of exploitation within 30 days, so no active exploitation is confirmed.

What to do: Apply Microsoft's security update for the affected Office/Outlook builds as soon as it is available, prioritizing mail-reviewer and helpdesk workstations that open untrusted email and documents; check Microsoft's advisory for the exact fixed build numbers for each Office version since they are not listed in this data. In the interim, caution users against opening attachments or embedded content from unknown senders, and confirm remediation by verifying Outlook/Word build numbers against the advisory. No workarounds are specified in the source data.

Affected
Microsoft Office Outlook
Microsoft Word
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Microsoft 365 Apps
Estimated exposure
masshundreds of millions of users (Office/Outlook is deployed on the vast majority of enterprise and consumer Windows desktops) — Microsoft Office and Outlook are near-ubiquitous in enterprise and consumer environments, so even a subset of the roughly 400M+ commercial Microsoft 365/Office seats implies an exposure base well above the mass threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.