CVE-2026-33115

8.4

Microsoft · Office Word

A use after free vulnerability in Microsoft Office Word allows an unauthorized local attacker to execute arbitrary code.

Executive summary

A critical use after free vulnerability exists in Microsoft Office Word, which could allow an unauthorized attacker to achieve local code execution.

Vulnerability

This vulnerability is a use after free condition (CWE-416) within Microsoft Office Word. The issue allows an unauthorized attacker with local access to the system to potentially execute arbitrary code by manipulating memory after it has been freed.

Business impact

The ability for an unauthorized user to execute code locally poses a severe threat to system integrity and confidentiality. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the corporate network. Given the CVSS score of 8.4, this vulnerability is classified as High severity and requires immediate attention to prevent privilege escalation or malicious software installation.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft for the affected Office products as documented in the Microsoft Security Update Guide.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected crashes in Microsoft Word applications that may indicate exploitation attempts.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious file execution, and restrict user permissions to prevent unauthorized software installation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk posed by this use after free vulnerability is significant for all enterprise environments utilizing the affected versions of Microsoft Office. Administrators should prioritize the deployment of the official patches to all workstations and servers. Given the potential for total impact, failure to remediate this vulnerability leaves endpoints vulnerable to unauthorized code execution and subsequent system compromise.

More Microsoft CVEs

Sources