Executive brief
Microsoft Office is a suite of productivity applications used globally for document creation and data management. A security vulnerability has been identified that could allow an attacker to run malicious code on a user's computer if the user opens a specially crafted file. This could lead to a full system compromise, unauthorized access to sensitive files, or disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office. The vulnerability is triggered when the application improperly handles memory allocation while processing a malicious file. An attacker can exploit this by convincing a user to open a specially crafted document, leading to local code execution with the privileges of the logged-in user. The attack requires user interaction (UI:R) but no prior administrative privileges (PR:N). Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: NVD and MSRC advisory published