Executive brief
A security vulnerability has been identified in Microsoft Word, the widely used word processing application. This flaw allows an attacker to execute unauthorized code on a user's computer, potentially leading to a full system takeover or the theft of sensitive documents. Because the attack occurs locally, it typically involves a user opening a malicious file or an attacker already having limited access to the machine.
Technical details
A type confusion vulnerability (CWE-843) exists within Microsoft Office Word, potentially involving heap-based buffer overflows (CWE-122) and the use of uninitialized resources (CWE-908). The flaw is triggered when the application accesses a resource using an incompatible type, leading to memory corruption. An attacker can exploit this to achieve local code execution with the privileges of the current user. While the attack vector is classified as local, it typically requires the victim to open a specially crafted document. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Word
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft released the security advisory and NVD published the CVE record.