Executive brief
Microsoft Office Word is a widely-used word processing application. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by crafting a malicious Word document. An attacker could gain full control over the affected system, steal sensitive data, or install malware.
Technical details
A stack-based buffer overflow exists in Microsoft Office Word, a core component of the Microsoft Office suite. The vulnerability is triggered when Word processes a specially crafted document, causing a stack-based memory corruption. The attack requires local interaction—a user must open the malicious document—but does not require authentication or special privileges. Successful exploitation allows arbitrary code execution with the privileges of the user running Word. Microsoft has released a security update to address this vulnerability.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed