HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-45457Published Modified CNA microsoft

CVE-2026-45457: Microsoft Word Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
https://aka.ms/OfficeSecurityReleases
Affected Products
4

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An untrusted pointer dereference vulnerability in Microsoft Word allows an attacker to execute arbitrary code on a victim's machine. The attack is local in execution, meaning it requires the victim to open a specially crafted document, but no authentication or account privileges are needed on the part of the attacker. Successful exploitation gives the attacker full code execution with the permissions of the user running Word, enabling complete confidentiality, integrity, and availability impact. A patched-image rebuild is available on HarborGuard for environments running affected versions of Microsoft 365 Apps for Enterprise.

HarborGuard Coverage

Detection

Detection for CVE-2026-45457 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Microsoft Office components. Any image found to carry an affected version of Microsoft 365 Apps for Enterprise is flagged immediately.

Available
Triage

HarborGuard scores this finding at CVSS 7.8 HIGH and is capable of weighting that score against each customer environment's compliance policy to reflect local risk tolerance. Findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pointed at the fix reference published by Microsoft is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityNot required

    The attacker does not need network access to the target; exploitation happens locally on the host where the document is opened.

  • AuthenticationNot required

    No account credentials or privileges are required from the attacker to trigger the vulnerability.

  • Victim interactionRequired

    The victim must open a specially crafted Word document, making this a social-engineering vector that relies on the user taking an action.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • Reads any file or data accessible to the user running Word, including stored credentials, documents, and session tokens.
  • Writes or modifies files and data within the user's permission scope, including persisted documents and configuration files.
  • Crashes or disrupts the Word process and any dependent workflows running under the same user account.
  • Executes arbitrary code at the privilege level of the logged-in user, which can serve as a foothold for further lateral movement if that user holds elevated rights.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-45457 is active as soon as the CVE enters the upstream feed, and any image bundling an affected version of Microsoft 365 Apps for Enterprise is flagged within minutes of publication. Where compliance policy permits, HarborGuard can rebuild affected images against the fix reference at https://aka.ms/OfficeSecurityReleases; for customers with auto-remediation enabled, that rebuild is followed by an automated regression run and a pull request opened against affected workloads. Median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Because this exploit requires victim interaction via a malicious document, teams that cannot immediately patch should consider restricting the file types permitted to reach end users (for example, blocking untrusted .docx and .rtf attachments at the network boundary) as a compensating control until the patched image is deployed.

See how HarborGuard automates this

Fix available

https://aka.ms/OfficeSecurityReleases
Affected packages
  • Microsoft / Microsoft 365 Apps for Enterprise
    < https://aka.ms/OfficeSecurityReleases (from 16.0.1)
  • Microsoft / Microsoft Office 365 for Mac
    -
  • Microsoft / Microsoft Office LTSC for Mac 2021
    -
  • Microsoft / Microsoft Office LTSC for Mac 2024
    -
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C