CVE-2026-69671
8.8Microsoft · Microsoft 365 Apps for Enterprise
A heap-based buffer overflow in Microsoft Office Word allows an unauthenticated, remote attacker to execute arbitrary code on the target system.
Executive summary
A heap-based buffer overflow vulnerability in Microsoft Word allows remote attackers to execute code, posing a high risk to organizational endpoints.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered within Microsoft Word. An unauthenticated attacker can exploit this via a network vector, though the attack typically requires user interaction.
Business impact
Successful exploitation allows for remote code execution, which can lead to complete system compromise, unauthorized data access, and lateral movement within the network. With a CVSS score of 8.8, this vulnerability is classified as High severity, reflecting the potential for full loss of confidentiality, integrity, and availability of the affected host.
Remediation
Immediate Action: Update affected Microsoft Office products to the specified fixed versions: 16.0.20326.20138 for 365 Apps, 16.0.10417.20207 for 2019, 16.0.14334.20906 for LTSC 2021, and 16.0.17932.20976 for LTSC 2024.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning from Winword.exe or unexpected network connections originating from Office applications.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious document execution patterns and utilize network filtering to restrict suspicious outbound traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the capability for remote code execution and the high CVSS score, organizations should prioritize patching all affected Microsoft Office installations. Please ensure that the latest security updates are applied across all enterprise workstations to mitigate the risk of exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Word Remote Code Execution Vulnerability Vendor advisory