Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications including Word, Excel, and PowerPoint. An attacker could exploit this flaw to gain unauthorized access to information stored on a user's local computer. To be successful, an attacker would typically need to trick a user into opening a specially crafted file.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to the disclosure of sensitive information from the process memory. The attack is local in nature and requires user interaction. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise All versions prior to July 2024 updates
- Microsoft Microsoft Office 2016 versions prior to 16.0.5561.1000
- Microsoft Microsoft Office 2019 All versions prior to July 2024 updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 All versions prior to July 2024 updates
- Microsoft Microsoft Office LTSC 2024 All versions prior to July 2024 updates
- Microsoft Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5561.1001
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory