Heap Buffer Overflow RCE in Microsoft Word (Office 2016-2024, Microsoft 365 & Apps)
AI analysis
A heap-based buffer overflow (CWE-122) in Microsoft Word's document processing allows an unauthorized, remote attacker to execute arbitrary code when the user opens or previews attacker-supplied Word document content, with the CVSS vector indicating no privileges required but user interaction needed. A successful attacker gains code execution in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. Anyone running Word from Office 2016, 2019, 2021, or 2024, Microsoft 365, or Microsoft 365 Apps is affected. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days, indicating no known exploitation in the wild.
What to do: Apply Microsoft's September 2026 security updates (or later channel builds) on all systems running Office 2016, 2019, 2021, 2024, Microsoft 365, or Microsoft 365 Apps, and confirm the installed Word build is post-patch via the Office Account/About panel. Until patched, instruct users not to open unsolicited Word document attachments and rely on Protected View, since exploitation requires user interaction. With no public PoC, KEV listing, or confirmed in-the-wild exploitation, this can be handled in the normal patch cycle, but the 8.8 CVSS and Word's ubiquitous document-opening attack surface justify prompt prioritization.
Affected
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Estimated exposure
masshundreds of millions of users (Word is bundled in Microsoft 365 and every supported Office release) — Microsoft 365/Office is the dominant desktop productivity suite with an install base measured in the hundreds of millions of seats, and every listed product includes the vulnerable Word component, though actual risk applies only to users…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.