Junglewise Threat Intelligence

CVE-2026-78507: Microsoft Office Word use-after-free remote code execution

CVE-2026-78507 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word contains a use-after-free vulnerability that allows an attacker to execute arbitrary code on a user's computer through specially crafted Word documents delivered over the network. Exploitation requires no special user privileges and could lead to complete system compromise, data theft, or malware installation on affected systems.

Technical details

The vulnerability is a use-after-free memory corruption flaw in Microsoft Office Word that occurs when the application improperly manages memory during document parsing. An attacker can exploit this by crafting a malicious Word document (.docx or related format) that triggers the use-after-free condition when opened or processed by Word. The attack vector is network-based (document delivery), with minimal preconditions—typically just opening or previewing the malicious document. Successful exploitation allows remote code execution with the privileges of the Word process. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats