Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to gain access to sensitive information stored in the computer's memory that should otherwise be protected. To carry out this attack, a user would typically need to be tricked into opening a specially crafted file.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office. The flaw is triggered when the application reads data past the end of the intended buffer, which can lead to the disclosure of sensitive information from the process memory. The attack vector is local, but it requires user interaction, meaning a victim must open a malicious file or perform a specific action to trigger the exploit. Microsoft has assigned a CVSS score of 3.3, reflecting a low impact on confidentiality with no impact on integrity or availability.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory