Executive brief
A vulnerability in Microsoft Office could allow an attacker to run unauthorized code on a user's computer. This typically occurs when a user is tricked into opening a specially crafted file, potentially leading to a full system compromise or data theft. Organizations should ensure users apply the latest security updates for their Office productivity suite.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office. The vulnerability is triggered when the application improperly handles memory while processing a maliciously crafted file. An attacker can exploit this by convincing a user to open a specific file, leading to arbitrary code execution in the context of the current user. The attack vector is local and requires user interaction, as indicated by the CVSS:3.1/AV:L/AC:L/PR:N/UI:R vector. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory