Junglewise Threat Intelligence

CVE-2026-40366: Microsoft Office Word use after free code execution

CVE-2026-40366 · Severity: high · CVSS 8.4 · Published 2026-05-12

Technologies: Microsoft Word. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Word could allow an attacker to run unauthorized commands on a user's computer. Microsoft Word is a widely used word processing application, and this flaw could lead to a complete compromise of the affected system, including the theft of sensitive data or the installation of malicious software. An attacker would typically need local access or a way to trick a user into opening a malicious file to exploit this weakness.

Technical details

A use-after-free (UAF) vulnerability exists in Microsoft Office Word, identified as CWE-416. The flaw occurs when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by specifically crafting memory conditions to execute arbitrary code in the context of the current user. While the attack vector is classified as local, it typically involves a user opening a specially crafted document. Successful exploitation grants the attacker high privileges over confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability in their Security Update Guide.

Affected products

  • Microsoft Word

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Published by Microsoft and NVD

References

Related threats