CVE-2026-72973 – Microsoft Defender Business Heap Buffer Overflow
Severity: HIGH (CVSS 8.8)
Affected Product:
- Microsoft Defender Business
Vulnerability Details: Heap-based buffer overflow in Microsoft Office Word component enables remote code execution by an unauthorized attacker over a network.
KEV Status: Not currently listed as actively exploited
Remediation:
- Apply security updates from Microsoft
- Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72973
Recommendation: Prioritize patching due to network-exploitable remote code execution capability and high CVSS score.