CVE-2026-55032
Analyzed Analyzed - Analysis Complete

Use After Free in Microsoft Office Word Allows Code Execution

Vulnerability report for CVE-2026-55032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft word 2016
microsoft word 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55032 is a use-after-free vulnerability in Microsoft Office Word. This type of vulnerability occurs when a program continues to use memory after it has been freed, which can lead to unexpected behavior or allow an attacker to execute arbitrary code.

In this case, an unauthorized attacker can exploit this flaw to execute code locally on the affected system. The vulnerability is classified as a remote code execution (RCE) issue with a severity rating of Important.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-55032 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office Word or monitoring for unusual behavior related to Word processes.

For accurate detection, refer to Microsoft's official guidance or security tools that can scan for vulnerable software versions. Microsoft may provide updates or signatures for security products like Microsoft Defender for Office 365 or Microsoft Endpoint Configuration Manager.

Impact Analysis

If you are using a vulnerable version of Microsoft Office Word, this vulnerability could impact you in several ways:

  • An attacker could execute malicious code on your system, potentially gaining control over it.
  • Sensitive data stored or processed in Word documents could be accessed, modified, or stolen.
  • The attacker could install malware, create new user accounts, or perform other unauthorized actions on your system.

The CVSS base score of 7.8 indicates a high impact on confidentiality, integrity, and availability of the affected system.

Compliance Impact

This vulnerability could affect compliance with common standards and regulations in the following ways:

  • GDPR: If the vulnerability leads to unauthorized access or disclosure of personal data, it could result in a violation of GDPR requirements for data protection and breach notification.
  • HIPAA: For organizations handling protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access to PHI, violating HIPAA's security and privacy rules.
  • Other standards (e.g., ISO 27001, NIST): Failure to patch or mitigate this vulnerability could be seen as a lapse in maintaining required security controls, potentially leading to non-compliance.

Organizations should assess the risk posed by this vulnerability and take appropriate actions to maintain compliance with applicable regulations.

Mitigation Strategies
  • Apply the latest security updates provided by Microsoft for Microsoft Office Word. Refer to the Microsoft Update Guide for CVE-2026-55032 for patch details.
  • If a patch is not immediately available, consider disabling or restricting access to Microsoft Office Word until the vulnerability is addressed.
  • Monitor Microsoft's official communications for additional mitigation strategies or workarounds.
  • Ensure that endpoint protection solutions are updated to detect and block exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart