Junglewise Threat Intelligence

CVE-2026-40367: Microsoft Office Word untrusted pointer dereference

CVE-2026-40367 · Severity: high · CVSS 8.4 · Published 2026-05-12

Technologies: Microsoft Word, Microsoft Office Word. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Word, the widely used word processing application. This flaw allows an unauthorized attacker to execute malicious code on a user's computer. If exploited, this could lead to a complete system takeover, unauthorized access to sensitive documents, or the installation of malware, potentially disrupting business operations and compromising confidential data.

Technical details

This vulnerability is classified as an untrusted pointer dereference (CWE-822) within Microsoft Office Word. The flaw occurs when the application processes a specially crafted pointer from an untrusted source without proper validation, leading to memory corruption. An attacker can exploit this locally to execute arbitrary code with the privileges of the current user. While the attack vector is local, the CVSS 3.1 score of 8.4 reflects that no elevated privileges or user interaction are required for successful exploitation once the attacker has local access. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats