Executive brief
Microsoft Office is a suite of productivity applications widely used by organizations for document creation, spreadsheets, and presentations. A command injection vulnerability allows an attacker to execute malicious code on a user's computer if they open a specially crafted Office document, potentially leading to unauthorized system access, data theft, or malware installation.
Technical details
This vulnerability is a command injection flaw in Microsoft Office that arises from improper neutralization of special elements in user-supplied input. The vulnerability allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running the affected Office application. An attack requires user interaction (opening a malicious Office document), but no prior authentication is needed. Successful exploitation can result in local code execution, enabling an attacker to read, modify, or delete sensitive data, or establish persistence on the compromised system. A patch is expected to be available through Microsoft Security Updates.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed