Executive brief
A vulnerability in Microsoft Office Word could allow an attacker to execute malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted document. Successful exploitation could lead to a full compromise of the user's data and system access.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office Word and related SharePoint server components. The vulnerability is triggered when the application fails to properly validate input while processing a document, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, resulting in arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected Office and SharePoint versions.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise >= 16.0.1
- Microsoft Microsoft Office 2019 >= 19.0.0
- Microsoft Microsoft Office LTSC 2021 >= 16.0.1
- Microsoft Microsoft Office LTSC 2024 >= 16.0.0
- Microsoft Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
- Microsoft Microsoft Word 2016 < 16.0.5561.1000
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-55130 by Microsoft.