ZeroHour

CVE-2026-81952

mass

Heap Buffer Overflow RCE in Microsoft Word (Office 2016-2024, Microsoft 365 & Apps)

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

A heap-based buffer overflow (CWE-122) in Microsoft Word's document processing allows an unauthorized, remote attacker to execute arbitrary code when the user opens or previews attacker-supplied Word document content, with the CVSS vector indicating no privileges required but user interaction needed. A successful attacker gains code execution in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. Anyone running Word from Office 2016, 2019, 2021, or 2024, Microsoft 365, or Microsoft 365 Apps is affected. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days, indicating no known exploitation in the wild.

What to do: Apply Microsoft's September 2026 security updates (or later channel builds) on all systems running Office 2016, 2019, 2021, 2024, Microsoft 365, or Microsoft 365 Apps, and confirm the installed Word build is post-patch via the Office Account/About panel. Until patched, instruct users not to open unsolicited Word document attachments and rely on Protected View, since exploitation requires user interaction. With no public PoC, KEV listing, or confirmed in-the-wild exploitation, this can be handled in the normal patch cycle, but the 8.8 CVSS and Word's ubiquitous document-opening attack surface justify prompt prioritization.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Word is bundled in Microsoft 365 and every supported Office release) — Microsoft 365/Office is the dominant desktop productivity suite with an install base measured in the hundreds of millions of seats, and every listed product includes the vulnerable Word component, though actual risk applies only to users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.