CVE-2026-45486: Microsoft Word Remote Code Execution Vulnerability
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- https://aka.ms/OfficeSecurityReleases
- Affected Products
- 4
HarborGuard Analysis
Synopsis
An untrusted pointer dereference vulnerability in Microsoft Word allows a local attacker to execute arbitrary code on the affected system. The attack requires no authentication but does require a user to open a maliciously crafted document, making this a classic file-based social engineering vector. Successful exploitation gives the attacker full code execution in the context of the logged-in user, enabling data theft, file modification, or further system compromise. A patched-image rebuild is available on HarborGuard for environments running affected versions of Microsoft Office products in containerized workloads.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Microsoft Office components.
AvailableHarborGuard scores this finding at CVSS 7.8 HIGH using the upstream v3.1 vector, and per-environment compliance policy weighting is applied to prioritize routing and alert severity. Findings are directed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.
AvailableA patched-image rebuild targeting the fix version referenced in the Microsoft Office Security Releases advisory becomes available through HarborGuard once the upstream package is published. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host; no over-the-network access to the service is required to trigger the vulnerability.
- AuthenticationNot required
No account or credentials are required; the attacker can trigger the vulnerability as an unauthenticated user as long as they can deliver the malicious document.
- Victim interactionRequired
A user must open a specially crafted Word document, meaning the attacker must convince a target to interact with a malicious file.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special environmental conditions, race conditions, or memory layout requirements on the attacker.
Blast Radius
- The attacker executes arbitrary code in the context of the user who opened the document, inheriting all file system and network permissions of that account.
- Confidential files, stored credentials, and session tokens accessible to the user account are exposed to the attacker.
- The attacker can modify or delete documents, configuration files, and other user-writable data on the host.
- The compromised user session can serve as a foothold for lateral movement or privilege escalation within the broader environment.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-45486 is active across all connected registries and build pipelines, with match results surfaced at CVSS 7.8 HIGH. For environments that include container images bundling Microsoft Office or Microsoft 365 components, a rebuild against the patched release referenced at the Microsoft Office Security Releases page becomes available as soon as the upstream package is published. For customers with auto-remediation enabled, HarborGuard triggers a patched rebuild, executes regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where auto-remediation is not enabled, HarborGuard surfaces the finding in the dashboard for manual review and tracks the advisory each ingest cycle to reflect fix availability as it changes.
Fix available
- Microsoft / Microsoft 365 Apps for Enterprise< https://aka.ms/OfficeSecurityReleases (from 16.0.1)
- Microsoft / Microsoft Office 365 for Mac-
- Microsoft / Microsoft Office LTSC for Mac 2021-
- Microsoft / Microsoft Office LTSC for Mac 2024-
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C