CVE-2026-23657: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23657?
CVE-2026-23657 is classified as a critical severity remote code execution vulnerability in Microsoft Word.
How do I fix CVE-2026-23657?
To fix CVE-2026-23657, apply the latest security updates from Microsoft for affected versions of Microsoft Office.
What types of software are affected by CVE-2026-23657?
CVE-2026-23657 affects Microsoft Office LTSC 2024 for both 32-bit and 64-bit editions, as well as Microsoft 365 Apps for Enterprise.
What does the exploit of CVE-2026-23657 allow an attacker to do?
Exploitation of CVE-2026-23657 allows an unauthorized attacker to execute arbitrary code locally on the victim's machine.
What is a 'use after free' vulnerability in the context of CVE-2026-23657?
In the context of CVE-2026-23657, a 'use after free' vulnerability occurs when Microsoft Word attempts to access memory after it has been freed, potentially allowing code execution.