Junglewise Threat Intelligence

CVE-2026-64907: Microsoft Office Word stack-based buffer overflow

CVE-2026-64907 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used word processing application. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by crafting a malicious Word document. An attacker could gain full control over the affected system, steal sensitive data, or install malware.

Technical details

A stack-based buffer overflow exists in Microsoft Office Word, a core component of the Microsoft Office suite. The vulnerability is triggered when Word processes a specially crafted document, causing a stack-based memory corruption. The attack requires local interaction—a user must open the malicious document—but does not require authentication or special privileges. Successful exploitation allows arbitrary code execution with the privileges of the user running Word. Microsoft has released a security update to address this vulnerability.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats