Executive brief
A security vulnerability exists in several versions of Microsoft Office that could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data or cause the application to crash, impacting both data confidentiality and system stability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office across multiple versions, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. The flaw is triggered when the application processes a specially crafted file, leading to memory access outside of intended buffers. An attacker can exploit this locally by convincing a user to open a malicious document (User Interaction required). Successful exploitation can result in the disclosure of sensitive information from the process memory or a denial-of-service condition. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office 2016 < 16.0.5561.1000
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft 365 Apps for Enterprise All versions
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Office LTSC for Mac 2021 < 16.111.26071215
- Microsoft Office LTSC for Mac 2024 < 16.111.26071215
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft
- 2026-07-14: advisory: NVD record published