Executive brief
Microsoft Office Word contains a double free memory safety vulnerability that allows an attacker to execute malicious code on a user's computer over the network. A user needs only to open a specially crafted document to trigger the vulnerability, potentially leading to complete system compromise and data theft.
Technical details
A double free vulnerability exists in Microsoft Office Word's memory management, where the same memory region is freed twice during document parsing. The vulnerability is triggered when processing a specially crafted Word document, requiring no authentication and exploitable remotely through document sharing or embedding. An attacker can achieve arbitrary code execution with the privileges of the user running Word. The vulnerability carries a CVSS score of 8.8, indicating high severity with network-based attack capability.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed