Executive brief
A security vulnerability exists in Microsoft Word, the widely used word processing application. An attacker could exploit this flaw by tricking a user into opening a specially crafted document, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized software installation, or disruption of business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in Microsoft Office Word. The vulnerability is triggered when the application fails to properly validate input while parsing a document, leading to memory corruption. An attacker can exploit this by convincing a target user to open a malicious Word document. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across affected versions of Office and SharePoint Server.
Affected products
- Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, SharePoint Server
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft published the security update guide.