Junglewise Threat Intelligence

CVE-2026-72973: Microsoft Office Word heap-based buffer overflow

CVE-2026-72973 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word contains a heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a user's computer over the network. Exploitation does not require user authentication or special privileges, making it a significant security risk for any organization using Office.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office Word's document parsing logic. The vulnerability allows an attacker to execute arbitrary code with the privileges of the user running Word by sending a specially crafted document over the network. The attack vector is network-based, and no user authentication is required, though the user must open or preview a malicious document. Successful exploitation could result in complete system compromise and code execution at the application level.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats