Executive brief
Microsoft Office is a widely-used suite of productivity applications deployed across most organizations. An integer overflow vulnerability in the software could allow a local attacker to execute malicious code on affected systems, potentially compromising sensitive business documents and data stored within Office files.
Technical details
An integer overflow or wraparound vulnerability exists in Microsoft Office that can be exploited through specially crafted Office documents. The vulnerability requires local access to the affected system and can lead to arbitrary code execution with the privileges of the user running Office. The attack does not require network access or user interaction beyond opening a malicious document. Microsoft has released a security update to patch this vulnerability.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed