Executive brief
Microsoft Office Word contains a memory reading flaw that allows an attacker to extract sensitive information from a user's system by crafting a malicious document. When a user opens the compromised document, the vulnerability exposes data that could include passwords, encryption keys, or other confidential information stored in memory.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing engine, allowing an attacker to read memory beyond allocated buffer boundaries. The vulnerability is triggered when Word processes a specially crafted document file, and requires user interaction (opening the malicious file). The attack vector is local; the attacker cannot exploit this remotely. A successful exploit results in information disclosure of sensitive data resident in process memory, without the ability to modify data or cause denial of service. Patches from Microsoft are available through the Security Update Guide.
Affected products
- Microsoft Office Word <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory