CVE-2026-70311: Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1000Patch KB5002901 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70311?
CVE-2026-70311 has a severity rating of 7.8, categorized as high.
How do I fix CVE-2026-70311?
To fix CVE-2026-70311, update Microsoft Office Word and related products to the latest version provided by Microsoft.
What type of vulnerability is CVE-2026-70311?
CVE-2026-70311 is classified as a remote code execution vulnerability due to a use after free condition.
Which products are affected by CVE-2026-70311?
CVE-2026-70311 affects Microsoft Word 2016, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, and Microsoft Office LTSC for Mac 2024.
What could an attacker achieve by exploiting CVE-2026-70311?
An attacker exploiting CVE-2026-70311 could execute unauthorized code locally on the affected system.