Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker who has gained local access to a system could exploit this flaw to run unauthorized commands or install malicious software. This could lead to a complete compromise of the affected computer, including the theft of sensitive documents and disruption of business operations.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office. While the primary description cites a buffer overflow, the associated CWE-416 suggests a Use-After-Free condition may also be involved in the memory corruption. The attack vector is local, meaning an attacker must already have a presence on the target system or entice a user to run a malicious file. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: NVD and Microsoft advisory published