Executive brief
Microsoft Office is a suite of productivity applications used across organizations for document creation and editing. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code locally with the privileges of the user running Office, potentially compromising sensitive business documents and enabling lateral movement within a network.
Technical details
A stack-based buffer overflow exists in Microsoft Office, allowing local code execution. The vulnerability is triggered through a local attack vector, requiring user interaction or local access to the affected system. An attacker can exploit this flaw to execute arbitrary code in the context of the Office application process, gaining the ability to read, modify, or delete files accessible to the user, or to establish persistence on the system. Patches are expected to be available from Microsoft through standard security update channels.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed