Executive brief
A security vulnerability has been identified in Microsoft Word, the widely used word processing application. This flaw could allow an attacker to run unauthorized commands or malicious software on a user's computer. If exploited, this could lead to a complete compromise of the affected system, including the theft of sensitive data or disruption of business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within Microsoft Office Word. The flaw is triggered when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this to execute arbitrary code in the context of the current user. While the attack vector is classified as local, it typically involves a user opening a specially crafted file. According to the CVSS vector, no elevated privileges or user interaction are strictly required for the execution phase once the vector is established. Microsoft has released information regarding this vulnerability in their Security Update Guide.
Affected products
- Microsoft Word
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Published by Microsoft and NVD