Junglewise Threat Intelligence

CVE-2026-62804: Microsoft Office Word path traversal remote code execution

CVE-2026-62804 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used word processor included in Microsoft Office suites. A path traversal vulnerability allows an attacker to manipulate file paths to execute arbitrary code locally, potentially compromising sensitive documents and enabling system-level attacks.

Technical details

This vulnerability involves external control of file name or path constructs in Microsoft Office Word, classified as a path traversal issue. An attacker can exploit improper input validation of file paths to reach and execute code on a local system. The attack requires local access or user interaction (e.g., opening a malicious document). Successful exploitation results in arbitrary code execution with the privileges of the user running Word. Microsoft has issued a security patch to address this vulnerability.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats