Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications including Word, Excel, and PowerPoint. An attacker could exploit this flaw to run malicious code on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full system compromise, allowing the attacker to steal sensitive data, install malware, or disrupt business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Office across Windows and macOS platforms. The vulnerability is triggered when the application improperly handles memory while processing a specially crafted file. Although the attack vector is local, it requires no prior privileges (PR:N) but does require user interaction (UI:R), such as opening a malicious document. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across affected versions of Office 2016, 2019, LTSC, and Microsoft 365 Apps.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to latest security release
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 up to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 up to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 up to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory