ZeroHour

CVE-2026-80080

mass

Double Free RCE in Microsoft Word

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

Microsoft Word contains a double free memory-corruption flaw (CWE-415) that Microsoft assigned an 8.8 High CVSS score, in which an unauthorized attacker can execute code over a network with no privileges required but user interaction needed. Consistent with the user-interaction requirement in the CVSS vector, exploitation almost certainly requires a user to open a specially crafted document delivered by the attacker. Successful exploitation yields arbitrary code execution in the context of the current user, with high confidentiality, integrity, and availability impact. All users of Microsoft Word shipped in Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024 are affected. As of the latest data there is no known in-the-wild exploitation, no public proof of concept, and EPSS estimates only a 0.6% probability of exploitation within 30 days (percentile 47).

What to do: Apply the Microsoft security update addressing CVE-2026-80080 through the Microsoft Update and Office update channels on all systems running Word in Microsoft 365 Apps, Microsoft 365, or Office 2019/2021/2024, and consult Microsoft's advisory for exact affected and fixed build numbers. Until patched, rely on user-interaction-dependent mitigations such as Protected View, warn-before-open policies, and caution with unsolicited documents, since exploitation requires opening attacker-supplied content. Prioritize patching workstations that routinely open external documents and monitor Microsoft and CISA channels for updated exploitation signals.

Affected
Microsoft Word
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Microsoft 365 Apps
Microsoft 365
Estimated exposure
masshundreds of millions of users (Word ships with essentially every Office/Microsoft 365 install) — Microsoft Office/Word is deployed on effectively every managed Windows desktop and across hundreds of millions of Microsoft 365/Office seats, so the unpatched Word population is plausibly on the order of 10^8 users.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.