Executive brief
A security vulnerability in Microsoft Office for Android could allow a user who already has basic access to a device to gain higher-level system permissions. This type of flaw is typically used by attackers to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked. The issue affects mobile versions of Office and Microsoft 365 Copilot.
Technical details
A vulnerability exists in Microsoft Office for Android (and Microsoft 365 Copilot) due to an integer overflow or wraparound condition, which can lead to a use-after-free scenario. An attacker with local access and low-privileged credentials can exploit this flaw to execute code with elevated privileges. The vulnerability is triggered during memory management operations where improper bounds checking allows for memory corruption. Microsoft has addressed this in version 16.0.19822.20000 and later.
Affected products
- Microsoft Office versions up to (excluding) 16.0.19822.20000
- Microsoft 365 Copilot versions up to (excluding) 16.0.19822.20000
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory: Microsoft released the security update guide.