Executive brief
Microsoft Office Word contains an out-of-bounds memory read vulnerability that allows an attacker with local access to extract sensitive information from the application's memory. An attacker would need to craft a malicious document or manipulate local system conditions to trigger the vulnerability, potentially exposing confidential data or credentials stored in Word's memory space.
Technical details
This vulnerability is an out-of-bounds read flaw in Microsoft Office Word's document parsing logic. The vulnerability requires local access to the affected system and does not propagate over the network. An attacker can exploit this by supplying a specially crafted document or input that causes the application to read memory beyond allocated buffer boundaries, resulting in information disclosure. The attack vector is local, meaning the attacker must have access to the compromised system to trigger the vulnerability.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed