Executive brief
Microsoft Office Word is a widely used word processor included in Microsoft Office suites. A path traversal vulnerability allows an attacker to manipulate file paths to execute arbitrary code locally, potentially compromising sensitive documents and enabling system-level attacks.
Technical details
This vulnerability involves external control of file name or path constructs in Microsoft Office Word, classified as a path traversal issue. An attacker can exploit improper input validation of file paths to reach and execute code on a local system. The attack requires local access or user interaction (e.g., opening a malicious document). Successful exploitation results in arbitrary code execution with the privileges of the user running Word. Microsoft has issued a security patch to address this vulnerability.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed