Junglewise Threat Intelligence

CVE-2026-45457: Microsoft Office Word untrusted pointer dereference

CVE-2026-45457 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Word. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw to run unauthorized code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full system compromise, allowing the attacker to steal data, install malware, or disrupt business operations.

Technical details

A vulnerability classified as an untrusted pointer dereference (and associated with CWE-125 Out-of-bounds Read) exists in Microsoft Word. The flaw is triggered when the application processes a malformed document, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, resulting in arbitrary code execution within the context of the logged-in user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Word

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Published by Microsoft and NVD

References

Related threats