Executive brief
Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to access sensitive information stored in memory on a local system. An unauthorized attacker could exploit this flaw to read confidential data without proper authorization, potentially exposing customer documents or system information.
Technical details
This vulnerability is an out-of-bounds read in the Microsoft Office Word document processing engine. The flaw occurs during local document parsing when Word reads beyond the bounds of an allocated memory buffer, exposing adjacent memory contents. An attacker would need to trick a user into opening a specially crafted Word document to trigger the vulnerability. The out-of-bounds read allows disclosure of information in memory but does not enable code execution. A patch is expected from Microsoft's security update process.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed