Junglewise Threat Intelligence

CVE-2026-64905: Microsoft Office Word buffer over-read in file parsing

CVE-2026-64905 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used document editing application. A buffer over-read vulnerability in Word's file parsing could allow an attacker with local access to execute arbitrary code on the affected system, potentially leading to complete system compromise.

Technical details

A buffer over-read vulnerability exists in Microsoft Office Word's document parsing functionality. The vulnerability allows an attacker to read beyond allocated memory boundaries when processing a specially crafted document file. An attacker with local file access can trigger this vulnerability by opening a malicious Word document, resulting in arbitrary code execution with the privileges of the user running Word. The attack requires user interaction (opening a file) and local or adjacent network access to deliver the malicious document.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats