Executive brief
Microsoft Office, a widely used suite of productivity applications, is affected by a security vulnerability that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. Successful exploitation could lead to a full compromise of the user's system, potentially resulting in data theft or unauthorized access to corporate resources.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office. The vulnerability is triggered when the application fails to properly validate input while processing a malicious file, leading to memory corruption. An attacker can exploit this by convincing a user to open a specially crafted document, achieving local code execution with the privileges of the logged-in user. The attack vector is local with a requirement for user interaction (UI:R), and it carries a high impact on confidentiality, integrity, and availability. Microsoft has released security updates to address this issue via the MSRC Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory