Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer, potentially leading to a full system takeover or theft of sensitive documents. To be successful, the attack requires a user to open a specially crafted file provided by the attacker.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office. The vulnerability is triggered when the application improperly handles memory while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local and requires user interaction, but does not require prior administrative privileges. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory