Executive brief
A security vulnerability exists in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw to run unauthorized code on a user's computer, potentially leading to a full system takeover or theft of sensitive documents. To be successful, the attack typically requires a user to open a specially crafted malicious file.
Technical details
A vulnerability classified as an untrusted pointer dereference (and associated with CWE-416 Use After Free) exists in Microsoft Office Word. The flaw allows for local code execution when a victim interacts with a malicious document. The attack vector is local with a low complexity, requiring no special privileges but necessitating user interaction (UI:R). Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability in their security update guide.
Affected products
- Microsoft Word
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory