cbcvebase.
CVE-2026-23657
published 2026-04-14

CVE-2026-23657: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftoffice_long_term_servicing_channel