Executive brief
Microsoft Office Word contains a use-after-free vulnerability that could allow an attacker to execute arbitrary code on a user's system through a specially crafted Word document. If exploited, an attacker could gain control over the user's computer, access sensitive documents, or deploy malware. The vulnerability requires user interaction (opening a malicious document) but has a high severity rating.
Technical details
This vulnerability is a use-after-free memory corruption flaw in Microsoft Office Word. The vulnerability allows remote code execution when a user opens a maliciously crafted Word document. The attack vector is network-based, requiring user interaction to open the document; no prior authentication is needed. Successful exploitation grants an attacker arbitrary code execution in the context of the user running Word. Microsoft has released a security update to address this issue, as indicated by the official Security Update Guide reference.
Affected products
- Microsoft Office Word <UNKNOWN>
Timeline
- 2026-09-08: disclosed