Executive brief
A vulnerability in Microsoft Word could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted document. If successful, the attacker could gain the same permissions as the user, potentially leading to data theft, unauthorized changes, or full system compromise.
Technical details
A use-after-free (CWE-416) vulnerability exists in Microsoft Office Word due to improper memory management. An attacker can exploit this by convincing a user to open a maliciously crafted file, triggering the execution of arbitrary code in the context of the current user. The attack vector is local, but it requires user interaction (UI:R) to open the document. The vulnerability affects multiple versions of Microsoft Office, including Microsoft 365 Apps, Office LTSC, and SharePoint Server. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to latest security release
- Microsoft Microsoft Office 2019 19.0.0 up to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 up to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 up to latest security release
- Microsoft Microsoft SharePoint Server Subscription Edition Affected
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-55032 by Microsoft
- 2026-07-14: advisory: NVD entry created and updated with Microsoft CNA data