Executive brief
Microsoft Word is a widely used word processing application for creating and editing documents. A security vulnerability in the software could allow an attacker to access sensitive information from the computer's memory if a user is tricked into opening a specially crafted file. While this requires user interaction, it could lead to the exposure of private data or contribute to further system compromise.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Word. The flaw is triggered when the application processes a specially crafted document, leading to memory disclosure. The attack vector is local, requiring a user to open a malicious file (User Interaction: Required). Successful exploitation allows an attacker to read sensitive information from the process memory, which could be used to bypass security mitigations like ASLR. Microsoft has released security updates to address this issue across affected versions of Microsoft 365 Apps and Office LTSC for Mac.
Affected products
- Microsoft 365 Apps for Enterprise versions prior to April 2026 updates
- Microsoft Office LTSC for Mac 2021 versions prior to 16.108.26041219
- Microsoft Office LTSC for Mac 2024 versions prior to 16.108.26041219
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Microsoft released the security update guide for this CVE.