CVE-2026-45471: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Other sources
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1000Patch KB5002879 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.110.26061317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20384Patch KB5002873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20153Patch KB5002876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5556.1005Fixed in 16.0.5556.1002Patch KB5002881
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45471?
CVE-2026-45471 has a severity rating of 7.8, classified as high.
How do I fix CVE-2026-45471?
To fix CVE-2026-45471, ensure that you apply the latest security updates provided by Microsoft for affected products.
What types of software are affected by CVE-2026-45471?
CVE-2026-45471 affects various versions of Microsoft Word, including 2016, Microsoft 365 Apps for Enterprise, and multiple editions of Microsoft Office LTSC.
What is the main risk of CVE-2026-45471?
The main risk of CVE-2026-45471 is that an unauthorized attacker can exploit the vulnerability to execute arbitrary code on the affected system.
When was CVE-2026-45471 published?
CVE-2026-45471 was published on June 9, 2026.