Description
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A classic double‑free flaw in Microsoft Office Word allows an unauthorized attacker to supply a specially crafted document that causes Word to release a memory block twice. The result is arbitrary code execution with the privileges of the user who opens the file, thereby compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects a broad range of Microsoft Office product lines for both Windows and macOS, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Microsoft Word 2016. All supported editions of these products are presumed vulnerable; no specific version ranges are provided in the advisory.

Risk and Exploitability

With a CVSS score of 8.8, the flaw is high severity and can be exploited over a network when a malicious document is opened. The EPSS score is not available, so exploitation frequency cannot be precisely determined. The condition that the flaw is not listed in the CISA KEV catalog suggests no widespread public exploitation to date, yet the ability to execute code remotely without user interaction makes it a serious threat for enterprises. The most likely attack vector is delivery of a crafted Word file via email, shared drives, or web download, which the victim then opens in Office.

Generated by OpenCVE AI on September 9, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update that contains the double‑free fix.
  • Configure Office or group policy to block opening documents from network shares or untrusted sources, and require user confirmation before opening such files.
  • Deploy Microsoft Defender Application Guard or a similar sandboxing solution to run Word in a protected environment that isolates document processing and prevents code execution outside the sandbox.

Generated by OpenCVE AI on September 9, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
Microsoft word
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft microsoft 365
Microsoft word

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Word Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
Weaknesses CWE-415
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:30.331Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80080

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:01.739Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:50.233

Modified: 2026-09-17T20:18:34.770

Link: CVE-2026-80080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T07:45:10Z

Weaknesses