Executive brief
Microsoft Office contains an out-of-bounds read vulnerability that allows a local attacker to read sensitive information from memory. An attacker with local access to an affected system could exploit this flaw to extract data such as passwords, encryption keys, or other confidential information stored in the application's memory.
Technical details
The vulnerability is an out-of-bounds read condition in Microsoft Office that permits local information disclosure. The flaw is triggered when the application processes certain inputs without proper bounds checking, allowing an attacker to read adjacent memory regions. This requires local access to the system where Office is installed. The attacker can leverage this to extract sensitive data from the Office process memory. A patch has been released by Microsoft as indicated by the Security Update Guide reference.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed