Executive brief
A vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in multiple versions of Microsoft Office, including Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps. The flaw is triggered when the application processes a specially crafted file, leading to an out-of-bounds memory read. An attacker can exploit this locally by convincing a user to open a malicious document (User Interaction required). Successful exploitation allows the attacker to disclose sensitive information from the process memory. Microsoft has released security updates to address this issue across affected platforms.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory