CVE-2026-72972
8.8Microsoft · Microsoft 365 Apps for Enterprise, Microsoft Office
A heap-based buffer overflow in Microsoft Office Word allows an unauthenticated attacker to achieve remote code execution over a network.
Executive summary
A critical heap-based buffer overflow vulnerability in Microsoft Office products permits remote code execution, posing a severe risk to organizational data and system integrity.
Vulnerability
The flaw is a heap-based buffer overflow (CWE-122) within Microsoft Office Word. It can be triggered by an unauthenticated attacker, though it requires user interaction to execute code successfully.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain code execution capabilities on the host system. Given the high CVSS score of 8.8, this poses a significant risk of unauthorized data access, potential lateral movement within the network, and complete system compromise. The impact is elevated by the ubiquity of the affected software within enterprise environments.
Remediation
Immediate Action: Apply the vendor-provided security updates immediately as outlined in the Microsoft Security Update Guide. Organizations must ensure that all instances of the affected Office versions are updated to the specified fixed build numbers.
Proactive Monitoring: Review endpoint and network logs for unusual process execution patterns originating from Word documents. Monitor for anomalous network traffic that may indicate an attempt to deliver a malicious payload.
Compensating Controls: Utilize endpoint detection and response (EDR) solutions to identify and block suspicious child processes spawned by Microsoft Office applications. Ensure that Macro security settings are strictly enforced via Group Policy to reduce the attack surface.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability represents a significant security weakness that could lead to full system compromise if left unpatched. Security teams should prioritize the deployment of the identified security updates across all affected endpoints. Organizations should verify that automated update mechanisms are functioning correctly to ensure comprehensive coverage across the enterprise.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office Word Remote Code Execution Vulnerability Vendor advisory