Sceawere

Vulnerability Detail

CVE-2026-70311UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Use After Free Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-416: Use After Free
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:19:08.410Z",
  "pubdate": "2026-08-11T17:19:08.410Z",
  "executiveSummary": "A use-after-free vulnerability exists in Microsoft Office Word, allowing an unauthorized local attacker to execute arbitrary code.\nThe vulnerability type is categorized as a use-after-free memory corruption flaw, which impacts Microsoft Office Word by compromising memory integrity.\nThe risk implications are severe, as successful exploitation enables local attackers to achieve arbitrary code execution within the security context of the currently logged-on user.\nAttacker capabilities include the potential to manipulate dangling pointers and corrupt heap memory structures through specially crafted documents.\nExploitation requirements generally involve tricking a user into opening a malicious file locally using a vulnerable installation of Microsoft Office Word.",
  "technicalDetails": "The vulnerability stems from a use-after-free condition within the memory management architecture of Microsoft Office Word when handling specific object references.\nThe root cause is improper handling of heap memory during the lifecycle of document objects, where a pointer is referenced after the underlying memory has been deallocated.\nThe vulnerable component resides within the core document parsing and rendering engine of Microsoft Office Word.\nAuthentication requirements are none for local exploitation, and the attacker relies on the victim interacting with a crafted file.\nPrivilege requirements are low, as the attack can be executed under the standard user privileges assigned to the application process.\nNetwork exposure is local, requiring the malicious payload to be delivered and opened on the target machine.\nThe step-by-step attack flow begins when an unauthorized attacker crafts a malicious document designed to trigger improper memory deallocation and subsequent reuse of the dangling pointer.\nWhen the user opens the file in Microsoft Office Word, the application parses the malicious structure, causing the execution flow to reference the freed memory address.\nPayload behavior involves manipulating the newly allocated heap data to hijack the execution pointer, leading to arbitrary code execution.\nThe post-exploitation impact allows the attacker to execute local commands, deploy further malware, or compromise sensitive user data."
}
CVE-2026-70311: Microsoft Office Word Use After Free Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere