
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33114 is an untrusted pointer dereference vulnerability in Microsoft Office Word that allows an unauthorized local attacker to execute arbitrary code. It was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security update cycle. Affected products include Microsoft Office 2021, Office 2024, Office LTSC 2021 and 2024 (Windows and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by Microsoft (Microsoft MSRC, GitHub Advisory).
The root cause is classified as CWE-822 (Untrusted Pointer Dereference), where Microsoft Office Word obtains a value from an untrusted source, converts it to a pointer, and dereferences the resulting pointer without adequate validation. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). This combination suggests the vulnerability may be triggered through a maliciously crafted Office document or local file that, when processed by Word, causes the application to dereference a controlled pointer value, leading to code execution. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability, potentially enabling complete compromise of the affected system. An attacker who exploits this vulnerability could execute arbitrary code in the context of the Word process, potentially accessing sensitive documents, modifying data, or disrupting application availability. The affected scope spans multiple Office product lines across both Windows and macOS platforms, including enterprise deployments via Microsoft 365 Apps (Microsoft MSRC).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.044% (0.000440), indicating a low near-term probability of exploitation. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 306451) and Qualys (plugin 110522) (GitHub Advisory, Feedly).
Microsoft released security updates on April 14, 2026, addressing this vulnerability across all affected products. For macOS versions, the fixed build is 16.108.26041219 or later (applicable to Office LTSC for Mac 2021 and 2024). For Windows-based Office 2021, Office 2024, and Microsoft 365 Apps for Enterprise, updates are available through Microsoft's security update guide at https://aka.ms/OfficeSecurityReleases. Organizations should apply the April 2026 Patch Tuesday updates immediately, prioritizing systems running Microsoft 365 Apps for Enterprise due to their broad deployment footprint. No configuration-based workarounds have been published by Microsoft (Microsoft MSRC).
CVE-2026-33114 was covered as part of broader April 2026 Patch Tuesday roundups by multiple security vendors and researchers. Coverage appeared in BleepingComputer, Qualys, Talos Intelligence, Zero Day Initiative, CrowdStrike, and Sophos, all noting it as one of 167 vulnerabilities addressed in what was described as one of the largest Patch Tuesday releases on record. No specific researcher commentary or notable social media discussion focused exclusively on this CVE was identified (BleepingComputer, Qualys Blog, Talos Intelligence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."