Junglewise Threat Intelligence

CVE-2026-81952: Microsoft Office Word heap buffer overflow

CVE-2026-81952 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word, a widely-used word processor for creating and editing documents, contains a heap-based buffer overflow vulnerability. An attacker can exploit this flaw over the network to execute arbitrary code without authorization, potentially compromising user systems, stealing sensitive documents, or deploying malware.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word that enables remote code execution. The vulnerability allows an attacker on the network to trigger the overflow condition, leading to arbitrary code execution with the privileges of the user running Word. No authentication is required; exploitation can occur by delivering a specially crafted document. The attack vector is network-based, and patches are available from Microsoft's Security Response Center.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats