Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw allows an unauthorized person to run malicious code on a user's computer if they have local access. Such an exploit could lead to a total loss of confidentiality, data integrity, and system availability, potentially allowing an attacker to steal sensitive documents or install malware.
Technical details
A type confusion vulnerability exists in Microsoft Office, which is also categorized as a heap-based buffer overflow (CWE-122). The flaw occurs when the application accesses a resource using an incompatible type, leading to memory corruption. An attacker with local access to the system can exploit this vulnerability without any prior authentication or user interaction. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the logged-in user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory