Executive brief
Microsoft Word, a widely used word processing application, contains a security flaw that could allow an attacker to run malicious code on a user's computer. If exploited, this could lead to a full system compromise, allowing unauthorized access to sensitive files, data theft, or the installation of malware. This affects various versions of Microsoft Office on both Windows and macOS.
Technical details
A use-after-free (UAF) vulnerability exists in Microsoft Office Word (CWE-416). The flaw is triggered when the application continues to use a pointer after it has been freed, potentially allowing an attacker to corrupt memory and gain control of the execution flow. While the attack vector is classified as local, an attacker who successfully exploits this can achieve full code execution with the privileges of the current user. The vulnerability affects Microsoft 365 Apps, Office LTSC 2021, and Office LTSC 2024 on both Windows and macOS platforms. Microsoft has released security updates to address this issue.
Affected products
- Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Office LTSC for Mac 2021 versions prior to 16.108.26041219
- Microsoft Office LTSC for Mac 2024 versions prior to 16.108.26041219
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Initial advisory published by Microsoft