Executive brief
A security vulnerability exists in Microsoft Word that could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to convince a user to open a specially crafted document. While the risk of a full system takeover is low, it could lead to the unauthorized disclosure of private data stored in the computer's memory.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Word. The vulnerability is triggered when the application processes a malformed document, leading to an out-of-bounds memory read. An attacker can exploit this by tricking a user into opening a malicious file, which could result in the disclosure of sensitive information from the process memory. The attack vector is local and requires user interaction (UI:R), with a CVSS base score of 3.3 indicating low impact on confidentiality and no impact on integrity or availability.
Affected products
- Microsoft Word
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory