Executive brief
Microsoft Office contains an out-of-bounds read vulnerability that allows an attacker with local access to read sensitive information from memory. This could expose confidential data such as document contents, cached credentials, or other user information stored in the application's memory. The vulnerability requires local access to exploit and poses a moderate information security risk.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Office, a memory safety issue where the application reads data beyond allocated buffer boundaries. An attacker with local access to the affected system can trigger this condition to disclose sensitive information from Office application memory. The attack vector is local, requiring direct system access or prior compromise. Microsoft has issued security updates to address this vulnerability; administrators should apply patches promptly to affected Office installations.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed