CVE-2026-78512: Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Other sources
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1003Patch KB5002914 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1002Patch KB4011160 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204
Event History
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The attacker can attempt exploitation over a network without authentication or prior privileges, but user interaction is required. The provided data does not specify the exact user action or delivery mechanism.
Which deployments should be prioritized for remediation?
Prioritize systems running the listed affected Word and Office products: Word 2016, Office 2016, Microsoft 365 Apps for Enterprise, Office 365 for Mac, and Office LTSC 2021 or 2024 in the listed 32-bit or 64-bit editions. Successful exploitation can result in code execution with high impacts to confidentiality, integrity, and availability.
Is there evidence that exploitation is already occurring?
The supplied data rates exploit code maturity as unproven. It does not state that exploitation has been observed in the wild.