
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20948 is an untrusted pointer dereference vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally. It was disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security updates. Affected products include Microsoft Word 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office LTSC 2021 and 2024 (Windows x86/x64 and macOS), SharePoint Server 2016, and SharePoint Server 2019. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning the application dereferences a pointer that originates from an untrusted source without adequate validation, enabling an attacker to redirect execution flow to arbitrary code. The attack vector is local (AV:L) with low attack complexity and no privileges required, but user interaction is required — typically opening a maliciously crafted Word document. The scope is unchanged, meaning exploitation is confined to the affected application's security context. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, Feedly).
Successful exploitation results in complete compromise of the affected system's confidentiality, integrity, and availability. An attacker who tricks a user into opening a malicious Word document can execute arbitrary code in the context of the logged-in user, potentially enabling data theft, file modification or deletion, malware installation, and persistent access. Given the broad deployment of Microsoft Office across enterprise environments, the potential blast radius is significant, though lateral movement would depend on the privileges of the compromised user account (Feedly, Microsoft MSRC).
Note: No public PoC or detailed exploitation technique has been published; these steps represent the general exploitation pattern for this class of vulnerability based on the CWE-822 classification and Microsoft's advisory description.
WINWORD.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a Word document is opened.%TEMP%, %APPDATA%, or startup folders by the Word process; newly created executable or script files in user-writable directories.WINWORD.EXE to external IP addresses or domains, particularly immediately after document opening; DNS queries for unusual or newly registered domains.WINWORD.EXE; application crash logs or Watson error reports referencing Word with unusual memory addresses.HKCU\Software\Microsoft\Windows\CurrentVersion\Run) created around the time of document access.Microsoft released patches for all affected products on January 13, 2026, as part of the January 2026 Patch Tuesday update cycle. Specific fixed versions include Microsoft Word 2016 (build 16.0.5535.1000 or later), SharePoint Server 2019 (16.0.10417.20083 or later), SharePoint Enterprise Server 2016 (16.0.5535.1001 or later), and Office LTSC for Mac 2021/2024 (16.105.26011018 or later); Microsoft 365 Apps for Enterprise and Office 2019/2021/2024 should be updated via the Office Security Releases channel. As interim mitigations, organizations should train users to avoid opening Word documents from untrusted sources, restrict macro execution via Group Policy, and consider enabling Protected View for documents from the internet. Applying the available patches is the definitive remediation (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets. Zero Day Initiative (ZDI) included it in their January 2026 Security Update Review, and BleepingComputer reported on the full Patch Tuesday release fixing 114 flaws including 3 zero-days (CVE-2026-20948 was not among the zero-days). Sophos, Lansweeper, and Petri also published Patch Tuesday summaries referencing the update. Community sentiment reflects routine patch prioritization given the lack of active exploitation, with no notable controversy or researcher-specific commentary on this CVE (ZDI Blog, BleepingComputer, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."