PatchSiren cyber security CVE debrief
CVE-2026-78517 Microsoft CVE debrief
A heap-based buffer overflow vulnerability exists in Microsoft Office Word, potentially allowing an unauthorized attacker to execute code over a network. This vulnerability, classified as CWE-122, has a CVSS score of 8.8, indicating high severity. Defenders should assess exposure, particularly in networked environments, and apply patches provided by Microsoft for the affected Office versions. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and weaknesses related to CWE-122. The vulnerability could allow remote code execution over a network, requiring immediate patching and verification of Office installations. Exposure of Microsoft Office
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-17
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-17
Who should care
Defenders responsible for Microsoft Office installations, particularly in networked environments, should assess exposure and apply patches. This includes IT administrators, security teams, and network administrators.
Why it matters
CVE-2026-78517 is a high-severity vulnerability in Microsoft Office Word that could allow remote code execution. Defenders should assess exposure, apply patches, and monitor for potential exploitation attempts.
- Potential remote code execution over a network requires immediate patching and verification of Office installations.
- Exposure of Microsoft Office Word to unauthorized attackers could lead to code execution.
- Defenders must verify inventory and ensure up-to-date patches for Office versions.
Technical summary
The vulnerability is a heap-based buffer overflow in Microsoft Office Word, which could allow an unauthorized attacker to execute code over a network. The CVSS score is 8.8, indicating a high severity. The CWE-122 weakness is associated with this vulnerability.
Defensive priority
Defenders should prioritize assessing exposure and applying patches for Microsoft Office Word, particularly in environments where Office is used over a network.
Recommended defensive actions
- Assess exposure of Microsoft Office Word installations, particularly in networked environments.
- Apply patches provided by Microsoft for the affected Office versions.
- Monitor network traffic for potential exploitation attempts.
- Verify inventory of Office installations and ensure they are up-to-date.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 8.8 and weaknesses related to CWE-122. The official CVE Program record (CVE-2026-78517) and NVD detail page (NVD) offer source-provided CVE metadata and vulnerability assessments. A patch is available from Microsoft for the affected Office versions. Defenders should verify inventory and ensure up-to-date patches for Office versions, especially in networked environments. The CVE record was
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78517
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.