ZeroHour

CVE-2026-80085

mass

Heap-Based Buffer Overflow in Microsoft Word Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-80085 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that allows an unauthorized, unprivileged attacker to execute code over a network. The CVSS vector requires user interaction (UI:R), consistent with the flaw being reached when a user opens crafted or malicious content handled by Word. Successful exploitation would let the attacker run arbitrary code in the context of the affected user, with high impact on confidentiality, integrity, and availability (CVSS 8.8). Affected deployments include Word across Microsoft 365 Apps, Microsoft 365, and Office 2019, 2021, and 2024. Exploitation status: none known - no public proof-of-concept, not in CISA KEV, and a low EPSS score of 0.5% (39th percentile).

What to do: Apply Microsoft's security update for this CVE to Word across Microsoft 365 Apps and Office 2019/2021/2024 as soon as it is published, and confirm installed builds through the Office update channel. Until patched, treat unsolicited Word documents as untrusted, keep Protected View and attachment sandboxing enabled, and monitor for the addition of a public PoC or KEV entry given the 8.8 severity.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
microsoft Word
Estimated exposure
masson the order of hundreds of millions of users (Word ships with Office/Microsoft 365) — Word is bundled with Microsoft Office and Microsoft 365, whose combined enterprise seats and consumer/retail installed base is measured in the hundreds of millions, so virtually any organization or individual running Office is plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.