Executive brief
A security vulnerability exists in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw by tricking a user into opening a specially crafted document, potentially allowing the attacker to take control of the victim's computer. This could lead to the theft of sensitive information, unauthorized changes to files, or a complete system compromise.
Technical details
A use-after-free vulnerability (CWE-416) exists in Microsoft Office Word. The flaw is triggered when the application attempts to access memory that has already been freed, typically during the processing of a maliciously crafted document. While the attack vector is classified as local, it requires user interaction (UI:R), meaning an attacker must persuade a user to open a compromised file. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user. Microsoft has released security updates to address this issue across various Office versions, including Microsoft 365 Apps and LTSC editions for both Windows and Mac.
Affected products
- Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Office LTSC for Mac 2021 versions prior to 16.108.26041219
- Microsoft Office LTSC for Mac 2024 versions prior to 16.108.26041219
Timeline
- 2026-04-14: disclosed: Initial disclosure by Microsoft Corporation
- 2026-04-14: advisory: NVD published date