Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker with local access to a system could exploit this flaw to run unauthorized code, potentially leading to a full system takeover or theft of sensitive documents. This poses a significant risk to data confidentiality and the overall integrity of the affected workstation.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office. While the NVD description cites a buffer overflow, the associated CWE-416 suggests a Use After Free condition may also be involved in the memory corruption. The attack vector is local, meaning an attacker must already have a presence on the system or entice a user to run a malicious file. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user, potentially leading to a complete compromise of the host. Users are advised to consult the Microsoft Security Update Guide for relevant patches.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory