Executive brief
Microsoft Office Word is a widely-used document editing application. A heap-based buffer overflow vulnerability could allow an attacker to execute malicious code on a user's computer with local access, potentially leading to data theft, system compromise, or malware installation.
Technical details
A heap-based buffer overflow exists in Microsoft Office Word, allowing an unauthorized attacker to execute arbitrary code with local privileges. The vulnerability is triggered through a malformed document that overflows a heap buffer during processing. An attacker must trick a user into opening a crafted Office document to exploit this flaw. Successful exploitation results in arbitrary code execution in the context of the user running Word. A security patch should be available through Microsoft's standard update channels.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed