ZeroHour

CVE-2026-78526

mass

Heap Buffer Overflow RCE in Microsoft Word (Office 2016–2024, Microsoft 365)

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-78526 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code over a network. The high CVSS vector requires user interaction (UI:R), which is consistent with the typical trigger: a victim opens or previews a specially crafted Word document, commonly delivered by email or a web link; no privileges or authentication are needed beforehand. On successful exploitation, the attacker gains code execution on the victim's machine, generally in the context of the logged-in user's privileges, potentially leading to full workstation compromise, data theft, and lateral movement. Anyone running Word through Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2016, 2019, 2021, and 2024 editions is affected. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, though Office RCE bugs are frequently weaponized once details or patch diffs become public.

What to do: Apply Microsoft's current security update for Word/Office (via Windows Update for Office 2016–2024 or the Microsoft 365 Apps update channel) and verify the installed Word build under File > Account > About Word after updating. Because exploitation requires user interaction, reinforce handling of unsolicited email attachments and consider disabling automatic document preview in mail clients until patching is complete. No public exploit is known, but prioritize hosts where users routinely open external documents.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Office/Microsoft 365 is among the most widely deployed desktop software suites worldwide) — Microsoft 365 and perpetual Office editions are installed on the large majority of corporate and consumer Windows desktops globally, so the plausibly affected installed base is on the order of hundreds of millions of users, far exceeding…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.