Executive brief
A security vulnerability has been identified in Microsoft Office Word and related SharePoint server components. This flaw could allow an attacker to execute malicious code on a user's computer if the user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the affected system, potentially resulting in data theft or unauthorized access to corporate resources.
Technical details
This vulnerability is classified as a double free (CWE-415) within Microsoft Office Word. The flaw occurs when the application attempts to free the same memory location twice, which can be leveraged by an attacker to corrupt memory and achieve arbitrary code execution. The attack vector is local, requiring a user to open a malicious document (User Interaction: Required). The vulnerability affects multiple versions of Microsoft Office on both Windows and macOS, as well as several SharePoint Server editions. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
- Microsoft Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
- Microsoft Microsoft SharePoint Server Subscription Edition All versions prior to security updates
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory