Executive brief
Microsoft Office contains an out-of-bounds read vulnerability that could allow an attacker with local access to read sensitive information from the application's memory. An attacker exploiting this issue could potentially access confidential documents, credentials, or other sensitive data stored in memory without authorization.
Technical details
This vulnerability is an out-of-bounds read flaw in Microsoft Office where improper bounds checking allows reading memory beyond allocated buffers. The vulnerability requires local access to the affected system and does not require user interaction or authentication. An attacker can leverage this to read arbitrary data from the Office application's memory, potentially exposing sensitive information such as document content or credentials. Microsoft has issued patches to address this issue.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed