Junglewise Threat Intelligence

CVE-2026-45643: Microsoft Office Word untrusted pointer dereference

CVE-2026-45643 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Word, Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Word, a widely used word processing application, contains a security vulnerability that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted document. Successful exploitation could lead to a full system compromise, allowing the attacker to view sensitive data, install programs, or disrupt business operations.

Technical details

A vulnerability classified as an untrusted pointer dereference (CWE-822) exists in Microsoft Office Word. The flaw occurs when the application processes a malformed document containing an invalid pointer, which an attacker can leverage to gain control of the execution flow. While the attack vector is local, it requires user interaction, such as opening a malicious file. If successfully exploited, an attacker can achieve arbitrary code execution with the privileges of the logged-in user. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats