CVE-2026-80085
massHeap-Based Buffer Overflow in Microsoft Word Allows Remote Code Execution
CVE-2026-80085 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that allows an unauthorized, unprivileged attacker to execute code over a network. The CVSS vector requires user interaction (UI:R), consistent with the flaw being reached when a user opens crafted or malicious content handled by Word. Successful exploitation would let the attacker run arbitrary code in the context of the affected user, with high impact on confidentiality, integrity, and availability (CVSS 8.8). Affected deployments include Word across Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024. Exploitation status: none known - no public proof-of-concept, not in CISA KEV, and a low EPSS score of 0.5% (39th percentile).
What to do: Apply Microsoft's security update for this CVE to Word across Microsoft 365 Apps and Office 2019/2021/2024 as soon as it is published, and confirm installed builds through the Office update channel. Until patched, treat unsolicited Word documents as untrusted, keep Protected View and attachment sandboxing enabled, and monitor for the addition of a public PoC or KEV entry given the 8.8 severity.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
| microsoft Word | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.