Junglewise Threat Intelligence

CVE-2026-55128: Microsoft Office Word use after free code execution

CVE-2026-55128 · Severity: high · CVSS 7.8 · Published 2026-07-14

Executive brief

Microsoft Office Word, a widely used word processing application, contains a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious document. Successful exploitation could lead to unauthorized access to sensitive data, installation of malicious software, or a complete system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in Microsoft Office Word (CWE-416). The flaw is triggered when the application improperly handles objects in memory, allowing an attacker to execute arbitrary code in the context of the current user. The attack vector is local, but it requires user interaction (UI:R), such as opening a malicious document. Affected products include Microsoft 365 Apps, Office 2019, Office LTSC 2021 and 2024, and several versions of SharePoint Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, SharePoint Server

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security updates.

References

Related threats