CVE-2026-33114
8.4Microsoft · Office Word
An untrusted pointer dereference vulnerability in Microsoft Office Word allows an unauthenticated attacker to execute code locally.
Executive summary
A critical untrusted pointer dereference vulnerability in Microsoft Office Word poses a severe risk of local code execution for users of affected enterprise and LTSC software versions.
Vulnerability
The flaw is an untrusted pointer dereference (CWE-822) that occurs within Microsoft Office Word. The vulnerability is exploitable by an unauthenticated attacker, potentially leading to unauthorized local code execution on the host machine.
Business impact
The vulnerability carries a CVSS score of 8.4, reflecting its high potential for total system compromise, including the loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user, which could result in data theft, lateral movement within the corporate network, or the installation of persistent malicious payloads.
Remediation
Immediate Action: Administrators must apply the latest Microsoft security updates immediately as outlined in the official Microsoft Security Update Guide.
Proactive Monitoring: Security teams should monitor endpoint activity for suspicious processes spawned by Microsoft Office applications, such as unexpected command-line arguments or unusual network connections.
Compensating Controls: Ensure that Endpoint Detection and Response (EDR) solutions are active and configured to block unauthorized child processes spawned from Office productivity software.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for code execution, this vulnerability represents a significant security risk to organizational workstations. IT departments should prioritize the deployment of the vendor-supplied patches across all affected Microsoft Office installations to prevent potential exploitation.
More Microsoft CVEs
Sources
- Microsoft Word Remote Code Execution Vulnerability Vendor advisory