CVE-2026-45457: Microsoft Word Remote Code Execution Vulnerability
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- https://aka.ms/OfficeSecurityReleases
- Affected Products
- 4
HarborGuard Analysis
Synopsis
An untrusted pointer dereference vulnerability in Microsoft Word allows an attacker to execute arbitrary code on a victim's machine. The attack is local in execution, meaning it requires the victim to open a specially crafted document, but no authentication or account privileges are needed on the part of the attacker. Successful exploitation gives the attacker full code execution with the permissions of the user running Word, enabling complete confidentiality, integrity, and availability impact. A patched-image rebuild is available on HarborGuard for environments running affected versions of Microsoft 365 Apps for Enterprise.
HarborGuard Coverage
Detection for CVE-2026-45457 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Microsoft Office components. Any image found to carry an affected version of Microsoft 365 Apps for Enterprise is flagged immediately.
AvailableHarborGuard scores this finding at CVSS 7.8 HIGH and is capable of weighting that score against each customer environment's compliance policy to reflect local risk tolerance. Findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pointed at the fix reference published by Microsoft is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityNot required
The attacker does not need network access to the target; exploitation happens locally on the host where the document is opened.
- AuthenticationNot required
No account credentials or privileges are required from the attacker to trigger the vulnerability.
- Victim interactionRequired
The victim must open a specially crafted Word document, making this a social-engineering vector that relies on the user taking an action.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- Reads any file or data accessible to the user running Word, including stored credentials, documents, and session tokens.
- Writes or modifies files and data within the user's permission scope, including persisted documents and configuration files.
- Crashes or disrupts the Word process and any dependent workflows running under the same user account.
- Executes arbitrary code at the privilege level of the logged-in user, which can serve as a foothold for further lateral movement if that user holds elevated rights.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-45457 is active as soon as the CVE enters the upstream feed, and any image bundling an affected version of Microsoft 365 Apps for Enterprise is flagged within minutes of publication. Where compliance policy permits, HarborGuard can rebuild affected images against the fix reference at https://aka.ms/OfficeSecurityReleases; for customers with auto-remediation enabled, that rebuild is followed by an automated regression run and a pull request opened against affected workloads. Median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Because this exploit requires victim interaction via a malicious document, teams that cannot immediately patch should consider restricting the file types permitted to reach end users (for example, blocking untrusted .docx and .rtf attachments at the network boundary) as a compensating control until the patched image is deployed.
Fix available
- Microsoft / Microsoft 365 Apps for Enterprise< https://aka.ms/OfficeSecurityReleases (from 16.0.1)
- Microsoft / Microsoft Office 365 for Mac-
- Microsoft / Microsoft Office LTSC for Mac 2021-
- Microsoft / Microsoft Office LTSC for Mac 2024-
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C