Executive brief
Microsoft Office Word contains a stack-based buffer overflow vulnerability that allows a local attacker to execute arbitrary code on the affected system. An attacker with local access could exploit this flaw by crafting a malicious Word document that, when opened, triggers the overflow and runs code with the privileges of the user opening the file. This could lead to complete system compromise, data theft, or unauthorized access to sensitive information.
Technical details
A stack-based buffer overflow exists in Microsoft Office Word due to insufficient input validation when processing specially crafted documents. The vulnerability can be triggered by opening a malicious Word file that overflows a stack buffer, allowing an attacker to overwrite adjacent memory and inject arbitrary code. The attack requires local access and user interaction (opening the malicious document); network vectors are not available. Successful exploitation results in code execution with the privileges of the user running Word. Microsoft has released patches to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed