Junglewise Threat Intelligence

CVE-2026-72972: Microsoft Office Word heap-based buffer overflow

CVE-2026-72972 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word is a widely-used document editor in enterprise and consumer environments. A heap-based buffer overflow vulnerability allows attackers to execute arbitrary code on a user's system by sending a specially crafted document over the network, potentially compromising sensitive data or enabling further system compromise.

Technical details

The vulnerability is a heap-based buffer overflow in Microsoft Office Word's document processing logic. The flaw can be triggered when Word processes a malicious document, allowing an attacker to corrupt heap memory and gain code execution. The attack is network-reachable and does not require prior authentication or special user privileges beyond opening a document. An attacker can achieve arbitrary code execution in the context of the user running Word. Patches are expected to be available from Microsoft through their regular security update cycle.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats