CVE-2026-45457ImportantRevised 19 Jun
Microsoft Word Remote Code Execution Vulnerability
Assessment
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- Severity
- Important
- CVSS base score
- 7.8CVSS:3.1/
AV:L/ AC:L/ PR:N/ UI:R/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 0.5%Higher than 37.9% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office Word
- Weakness
- CWE-125: Out-of-bounds Read
- Issued by
- Microsoft
- Published
- 9 Jun 2026 · June 2026
- Last revised
- 19 Jun 2026Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any actio…
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.