CVE-2026-69360

8.8

Microsoft · Office Word

A heap-based buffer overflow in Microsoft Office Word allows an unauthenticated remote attacker to execute arbitrary code via a malicious file.

Executive summary

A heap-based buffer overflow vulnerability in Microsoft Office Word on various Windows versions poses a high risk of remote code execution.

Vulnerability

This is a heap-based buffer overflow (CWE-122) occurring within Microsoft Office Word. The vulnerability allows an unauthenticated attacker to achieve remote code execution, provided the user interacts with a specially crafted file.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain the same privileges as the logged-in user, potentially leading to full system compromise, data exfiltration, or the installation of persistent malware. With a CVSS score of 8.8, this flaw represents a significant risk to organizational integrity and confidentiality, as it enables attackers to move laterally within the network once a system is compromised.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft for your specific Windows build version to reach the fixed build numbers identified in the metadata.

Proactive Monitoring: Monitor endpoint security logs for anomalous process spawning, particularly instances where Microsoft Word launches shell commands or network-facing utilities.

Compensating Controls: Deploy endpoint protection platforms capable of detecting heap-spraying or buffer overflow attempts, and ensure that Macro security settings are configured to block untrusted content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the high CVSS severity rating, organizations should prioritize the deployment of the latest Microsoft security patches across all affected Windows environments. System administrators should verify that all Office installations are updated to the specified non-vulnerable versions immediately to mitigate the risk of exploitation.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources