Executive brief
A security vulnerability has been identified in Microsoft Word, the widely used word processing application. This flaw allows an attacker to run malicious code on a user's computer, potentially leading to a full system takeover or the theft of sensitive documents. Because the attack happens locally, it typically requires the attacker to already have a presence on the machine or to trick a user into running a malicious file.
Technical details
A vulnerability classified as an untrusted pointer dereference (CWE-822) exists in Microsoft Office Word. The flaw occurs when the application improperly handles memory pointers from an untrusted source, which can be manipulated to redirect execution flow. An attacker with local access can exploit this to execute arbitrary code with the privileges of the current user. The vulnerability affects multiple versions of Office, including Microsoft 365 Apps and LTSC versions for both Windows and macOS. Microsoft has released security updates to address this issue.
Affected products
- Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Office LTSC for Mac 2021 versions prior to 16.108.26041219
- Microsoft, Office LTSC for Mac 2024 versions prior to 16.108.26041219
Timeline
- 2026-04-14: disclosed: Initial disclosure by Microsoft
- 2026-04-14: advisory: NVD entry published