Executive brief
Microsoft Office Word is a widely used document creation and editing application. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code locally on a system running a vulnerable version of Word, potentially compromising sensitive documents and enabling system takeover.
Technical details
A heap-based buffer overflow exists in Microsoft Office Word's document processing logic. The vulnerability is triggered when Word processes a specially crafted document, causing the application to write data beyond the bounds of an allocated heap buffer. An attacker must trick a user into opening a malicious document to exploit this vulnerability; no network access is required. Successful exploitation grants the attacker arbitrary code execution with the privileges of the user running Word. Microsoft has released patches to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed