Junglewise Threat Intelligence

CVE-2026-55127: Microsoft Office Word heap overflow code execution

CVE-2026-55127 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

A security vulnerability has been identified in Microsoft Office Word and related SharePoint services that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious file. If successful, the attacker could gain the same permissions as the local user, potentially leading to data theft, unauthorized software installation, or full system compromise.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Office Word. The vulnerability is triggered when the application fails to properly validate input while processing a specially crafted document. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Affected products include various versions of Microsoft Office (2019, LTSC 2021/2024), Microsoft 365 Apps, and SharePoint Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, Office for Mac, SharePoint Server

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via Microsoft MSRC.

References

Related threats