Microsoft Word Untrusted Pointer Dereference Vulnerability Allowing Local Code Execution

Vulnerability

A vulnerability exists in Microsoft Office Word due to untrusted pointer dereference, which allows an unauthorized attacker to execute code locally. This issue is classified as a remote code execution vulnerability, although the exploitation occurs on the local machine.

Impact

Exploitation of this vulnerability could lead to unauthorized local code execution.

Remediation

Users should apply the official security updates provided by Microsoft for Word. Instructions for downloading these updates can be found in the Microsoft Update Catalog.

Added: May 12, 2026, 7:41 PM
Updated: May 12, 2026, 7:41 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
2.7
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.