Executive brief
A security vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, allowing the attacker to read sensitive information from the process memory. This is a local attack vector requiring user interaction, with a CVSS base score of 5.5. Microsoft has released security updates to address this issue across affected products including Office 2016, 2019, LTSC, and Microsoft 365 Apps.
Affected products
- Microsoft Office 2016 < 16.0.5561.1000
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft 365 Apps for Enterprise All versions
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory