Executive brief
Microsoft Office Word contains a use-after-free vulnerability that allows an attacker to execute arbitrary code on a user's computer through specially crafted Word documents delivered over the network. Exploitation requires no special user privileges and could lead to complete system compromise, data theft, or malware installation on affected systems.
Technical details
The vulnerability is a use-after-free memory corruption flaw in Microsoft Office Word that occurs when the application improperly manages memory during document parsing. An attacker can exploit this by crafting a malicious Word document (.docx or related format) that triggers the use-after-free condition when opened or processed by Word. The attack vector is network-based (document delivery), with minimal preconditions—typically just opening or previewing the malicious document. Successful exploitation allows remote code execution with the privileges of the Word process. Microsoft has released patches to address this issue.
Affected products
- Microsoft Office Word <UNKNOWN>
Timeline
- 2026-09-08: disclosed