Executive brief
Microsoft Office Word is a widely used document editing application. A buffer over-read vulnerability in Word's file parsing could allow an attacker with local access to execute arbitrary code on the affected system, potentially leading to complete system compromise.
Technical details
A buffer over-read vulnerability exists in Microsoft Office Word's document parsing functionality. The vulnerability allows an attacker to read beyond allocated memory boundaries when processing a specially crafted document file. An attacker with local file access can trigger this vulnerability by opening a malicious Word document, resulting in arbitrary code execution with the privileges of the user running Word. The attack requires user interaction (opening a file) and local or adjacent network access to deliver the malicious document.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed