Executive brief
Microsoft Office is a suite of productivity applications used across enterprises and consumer devices. An integer overflow vulnerability in Microsoft Office could allow a local attacker to execute arbitrary code with elevated privileges, potentially compromising data, disrupting operations, or enabling further system compromise.
Technical details
The vulnerability is an integer overflow or wraparound condition in Microsoft Office that allows code execution via a local attack vector. An attacker with local access can trigger the integer overflow to achieve arbitrary code execution. No user interaction or authentication is required beyond local system access. The vulnerability has a CVSS score of 7.8 (high severity) and is not currently known to be exploited in the wild. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office <UNKNOWN>
Timeline
- 2026-08-11: disclosed