
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33115 is a use-after-free vulnerability in Microsoft Office Word that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security update cycle. Affected products include Microsoft Office LTSC 2021 (Windows and macOS), Microsoft Office LTSC 2024 (Windows and macOS), and Microsoft 365 Apps for Enterprise (x86 and x64). The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by Microsoft (Microsoft MSRC, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), meaning Microsoft Office Word improperly reuses or references memory after it has been freed, potentially allowing an attacker to execute arbitrary code in the context of the application. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L), making it straightforward to exploit once local access is established. No public technical write-ups or proof-of-concept code detailing the specific triggering mechanism have been identified at this time (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can execute arbitrary code locally within the context of Microsoft Office Word, potentially gaining unauthorized access to sensitive documents, modifying data, or disrupting application availability. Because no user interaction or privileges are required, an attacker with local access to a vulnerable system could exploit this flaw without any victim action. The scope is unchanged, meaning the impact is contained to the Office application and its accessible resources, though code execution could facilitate further lateral movement or privilege escalation on the host (Microsoft MSRC, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.044–0.063%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Microsoft released security updates on April 14, 2026, addressing this vulnerability as part of the April 2026 Patch Tuesday release. Affected users should apply updates through Microsoft Update or the Microsoft Update Catalog for Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise; macOS users should update to version 16.108.26041219 or later for Office LTSC for Mac 2021 and 2024. Organizations should prioritize patching given the high CVSS score and the lack of required user interaction for exploitation. No configuration-based workarounds have been published by Microsoft (Microsoft MSRC).
CVE-2026-33115 was covered as part of broader April 2026 Patch Tuesday roundups by multiple security outlets, including BleepingComputer, Qualys, Talos Intelligence, Zero Day Initiative, CrowdStrike, and Sophos, all noting it among the 167 vulnerabilities addressed in that cycle (BleepingComputer, Qualys Blog, Talos). The vulnerability attracted attention due to its unusual CVSS profile — local attack vector with no privileges or user interaction required — which security researchers noted as atypical for an Office Word flaw. No significant controversy or vendor disputes have been reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."