CVE-2026-69722
8.8Microsoft · Microsoft 365 Apps for Enterprise
A stack-based buffer overflow in Microsoft Office Word allows an unauthenticated attacker to achieve remote code execution over a network.
Executive summary
A critical stack-based buffer overflow vulnerability in Microsoft Office products permits unauthenticated remote code execution, posing a significant risk to organizational integrity.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring within Microsoft Office Word. An unauthenticated attacker can exploit this flaw to execute arbitrary code on the target system.
Business impact
Successful exploitation allows an attacker to gain full control over the affected workstation, potentially leading to unauthorized data access, lateral movement within the network, and complete system compromise. With a CVSS score of 8.8, this vulnerability is classified as High severity, reflecting the high potential for total loss of confidentiality, integrity, and availability of the host machine.
Remediation
Immediate Action: Apply the vendor-supplied security updates immediately by referencing the Microsoft Security Update Guide for the specific product version.
Proactive Monitoring: Monitor endpoint logs for suspicious process execution patterns originating from Microsoft Word, such as unexpected child processes spawning from winword.exe.
Compensating Controls: Ensure that Office macro security settings are configured to high, and utilize endpoint protection platforms to detect and block malicious document execution attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, organizations should prioritize the deployment of the provided security patches across all affected endpoints. Failure to remediate could allow attackers to bypass standard security controls, making immediate patch management essential to maintaining a secure environment.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Word Remote Code Execution Vulnerability Vendor advisory