Executive brief
A security vulnerability in Microsoft Office could allow an attacker to execute malicious code on a user's device. This issue occurs when the application incorrectly handles data in its memory, typically triggered if a user is tricked into opening a specially crafted file. Successful exploitation could lead to a full compromise of the application's data and potentially the underlying device.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office due to improper bounds checking during memory operations (CWE-787). The vulnerability is exploitable locally but requires user interaction, such as opening a malicious document. An attacker who successfully exploits this vulnerability could gain the ability to execute arbitrary code in the context of the current user. The flaw affects Microsoft Office and 365 Copilot on Android and Universal platforms, with patches available in versions 16.0.19127.20000 and 16.0.14326.22618 respectively.
Affected products
- Microsoft Office Android versions prior to 16.0.19127.20000, Universal versions prior to 16.0.14326.22618
- Microsoft 365 Copilot Android versions prior to 16.0.19127.20000
Timeline
- 2025-08-12: disclosed
- 2025-08-12: advisory: Microsoft published the security update guide.