Executive brief
A security vulnerability has been identified in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the victim's computer. This could lead to the theft of sensitive data, unauthorized access to corporate systems, or the installation of malicious software.
Technical details
A vulnerability classified as an untrusted pointer dereference (CWE-822) exists within Microsoft Office Word. The flaw is triggered when the application processes a maliciously crafted document containing an invalid pointer that the application fails to properly validate. While the attack vector is local, it requires user interaction (UI:R), typically involving a victim opening a malicious file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Word
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory