Executive brief
Microsoft Office Word is a widely used word processing application in enterprise and consumer environments. An out-of-bounds read vulnerability allows an attacker with local access to the system to disclose sensitive information from memory, potentially exposing confidential documents, cached data, or other sensitive content.
Technical details
This vulnerability is an out-of-bounds read in Microsoft Office Word's memory handling. The attack requires local access to the affected system. Successful exploitation allows an attacker to read memory outside allocated bounds, potentially disclosing sensitive information such as document content or other protected data. The vulnerability has a CVSS v3.1 score of 5.5, reflecting low confidentiality impact with local attack vector requirements. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed