Executive brief
Microsoft Office is a suite of productivity applications used by millions for document creation, spreadsheets, and presentations. An integer overflow vulnerability in Office could allow an attacker to execute malicious code on a user's computer when opening a specially crafted file, potentially leading to data theft, system compromise, or ransomware installation.
Technical details
An integer overflow or wraparound vulnerability exists in Microsoft Office, allowing for local code execution. The vulnerability occurs due to improper bounds checking in Office's file parsing logic, which can be triggered when processing specially crafted Office documents. An attacker must convince a user to open a malicious file to trigger the vulnerability; the attack does not require elevated privileges or network access. Successful exploitation results in arbitrary code execution in the context of the user running Office. Patches are available from Microsoft's Security Update Guide.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed