PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45471 Microsoft CVE debrief

CVE-2026-45471 is a HIGH severity vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally. The vulnerability is caused by an untrusted pointer dereference. Microsoft Office Word is a popular word processing software used by millions of users worldwide. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office 2024. Users should apply patches immediately to prevent exploitation.

Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-17
Advisory published
2026-06-09
Advisory updated
2026-06-17

Who should care

Organizations and individuals using Microsoft Office Word, particularly those using vulnerable versions, should apply patches immediately to prevent exploitation. This includes users of Microsoft 365 Apps, Office 2019, Office 2021, and Office 2024.

Technical summary

The vulnerability is caused by an untrusted pointer dereference in Microsoft Office Word, which allows an attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office 2024.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches for Microsoft Office Word as soon as possible
  • Use secure coding practices when developing software
  • Implement memory protection mechanisms to prevent exploitation
  • Conduct regular security audits and vulnerability assessments
  • Use antivirus software and keep it up to date
  • Be cautious when opening email attachments or clicking on links from unknown sources

Evidence notes

The vulnerability is documented in the CVE-2026-45471 record and the NVD detail page. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Official resources

CVE-2026-45471 was published on 2026-06-09T17:17:21.600Z and modified on 2026-06-17T19:36:55.073Z.