Executive brief
Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A security vulnerability has been identified that could allow an unauthorized person to access sensitive information on a computer if they can trick a user into opening a specially crafted file. While this does not allow for direct control of the system, it could lead to the exposure of private data or memory contents that could be used in further attacks.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office. The flaw is triggered when the application processes a specially crafted file, leading to memory disclosure. The attack vector is local, requiring a user to open a malicious file (User Interaction: Required). Successful exploitation allows an attacker to read sensitive information from the process memory, though it does not directly provide code execution or data integrity bypass. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2026-06-09: advisory: Microsoft MSRC advisory published.