Executive brief
Microsoft Word, a widely used word processing application, contains a security flaw that allows an attacker to bypass built-in security protections. By tricking a user into interacting with a malicious file, an attacker can gain elevated permissions on the victim's computer. This vulnerability is currently being exploited in the wild, posing a significant risk of unauthorized system access and data compromise.
Technical details
A vulnerability exists in Microsoft Office Word (CWE-807) where the application relies on untrusted inputs to make security decisions. This flaw allows an attacker to bypass security features locally, provided they can convince a user to perform a specific action, such as opening a specially crafted document. The vulnerability is classified as a Local Privilege Escalation (LPE) and has been confirmed by CISA to be exploited in the wild. Affected versions include Microsoft 365 Apps and Office LTSC 2021/2024 on both Windows and macOS. Users are advised to apply the security updates provided by Microsoft.
Affected products
- Microsoft Office Word 365 Apps, LTSC 2021, LTSC 2024
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory: Microsoft released vendor advisory and CISA added to KEV catalog
- 2026-02-10: exploited: Confirmed by CISA KEV entry