PatchSiren cyber security CVE debrief
CVE-2026-45471 Microsoft CVE debrief
CVE-2026-45471 is a HIGH severity vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally. The vulnerability is caused by an untrusted pointer dereference. Microsoft Office Word is a popular word processing software used by millions of users worldwide. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office 2024. Users should apply patches immediately to prevent exploitation.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-09
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-09
- Advisory updated
- 2026-06-17
Who should care
Organizations and individuals using Microsoft Office Word, particularly those using vulnerable versions, should apply patches immediately to prevent exploitation. This includes users of Microsoft 365 Apps, Office 2019, Office 2021, and Office 2024.
Technical summary
The vulnerability is caused by an untrusted pointer dereference in Microsoft Office Word, which allows an attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability affects various versions of Microsoft Office, including Office 2019, Office 2021, and Office 2024.
Defensive priority
HIGH
Recommended defensive actions
- Apply patches for Microsoft Office Word as soon as possible
- Use secure coding practices when developing software
- Implement memory protection mechanisms to prevent exploitation
- Conduct regular security audits and vulnerability assessments
- Use antivirus software and keep it up to date
- Be cautious when opening email attachments or clicking on links from unknown sources
Evidence notes
The vulnerability is documented in the CVE-2026-45471 record and the NVD detail page. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Official resources
-
CVE-2026-45471 CVE record
CVE.org
-
CVE-2026-45471 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
CVE-2026-45471 was published on 2026-06-09T17:17:21.600Z and modified on 2026-06-17T19:36:55.073Z.