Junglewise Threat Intelligence

CVE-2026-64915: Microsoft Office Word heap-based buffer overflow

CVE-2026-64915 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used document editing application. A heap-based buffer overflow vulnerability could allow an attacker to execute malicious code on a user's computer with local access, potentially leading to data theft, system compromise, or malware installation.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word, allowing an unauthorized attacker to execute arbitrary code with local privileges. The vulnerability is triggered through a malformed document that overflows a heap buffer during processing. An attacker must trick a user into opening a crafted Office document to exploit this flaw. Successful exploitation results in arbitrary code execution in the context of the user running Word. A security patch should be available through Microsoft's standard update channels.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats