Executive brief
Microsoft Office contains a vulnerability where untrusted data can cause a pointer dereference, allowing an attacker to execute arbitrary code on a user's computer. This could lead to complete compromise of the affected system, theft of sensitive documents, or lateral movement within an organization.
Technical details
The vulnerability is a classic untrusted pointer dereference in Microsoft Office, a memory corruption flaw where the application fails to validate a pointer before dereferencing it. An attacker can exploit this via a specially crafted Office document or file. The attack requires local code execution context but does not require elevated privileges or user interaction beyond opening a malicious document. Successful exploitation results in arbitrary code execution with the privileges of the user running Office.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed