Junglewise Threat Intelligence

CVE-2026-78517: Microsoft Office Word heap-based buffer overflow

CVE-2026-78517 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word, a widely used document processing application, contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code remotely. An attacker can exploit this flaw by crafting a malicious Word document and sending it to a target user, potentially leading to complete compromise of the user's system and access to sensitive documents and data.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word due to improper input validation when processing crafted document files. The vulnerability can be triggered by opening a specially malformed Word document, and does not require authentication or user privileges beyond the ability to open the file. An attacker can exploit this to achieve arbitrary code execution in the context of the user running Office. The attack vector is primarily network-based (delivery via email or web download), and successful exploitation provides the attacker with full execution capability on the affected system.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats