Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to gain unauthorized access to sensitive information on a user's computer. This typically requires a user to open a specially crafted file, which could lead to data theft or further compromise of the local system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office across Windows and macOS platforms. The flaw is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to local information disclosure and potentially full system compromise (as indicated by the high integrity and availability impact in the CVSS vector). The attack vector is local and requires user interaction. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory