Executive brief
A vulnerability in Microsoft Word could allow an unauthorized person to access sensitive information over a network. This occurs when the application incorrectly handles file paths or names provided by an external source. An attacker could potentially use this to view files or data they are not authorized to see, though it requires some level of user interaction.
Technical details
This vulnerability is classified as CWE-73 (External Control of File Name or Path) within Microsoft Office Word. It allows a remote, unauthenticated attacker to disclose sensitive information by manipulating file paths or names that the application processes. The attack vector is network-based and requires low architectural complexity, but it does necessitate user interaction (UI:R) to be successful. Exploitation results in a partial loss of confidentiality (C:L) without impacting system integrity or availability.
Affected products
- Microsoft Office Word
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft
- 2026-05-12: advisory: NVD record published