Executive brief
Microsoft Office Word is a widely used word processing application for creating and editing documents. A security vulnerability exists where an attacker could execute malicious code on a user's computer if the user is tricked into opening a specially crafted Word file. This could lead to a full system compromise, unauthorized data access, or the installation of malware.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in Microsoft Office Word, which can lead to a heap-based buffer overflow (CWE-122). The vulnerability is triggered when the application processes a specially crafted document. While the attack vector is local, it requires user interaction (UI:R), typically involving a victim opening a malicious file provided by the attacker. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office and SharePoint Server.
Affected products
- Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, Office for Mac, SharePoint Server
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory