Executive brief
Microsoft Office is a suite of widely-used productivity applications for document creation, spreadsheets, and presentations. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's system by crafting a malicious Office document, potentially leading to data theft, system compromise, or lateral movement within a network.
Technical details
A heap-based buffer overflow exists in Microsoft Office due to improper bounds checking when processing specially crafted input. The vulnerability is triggered when a user opens a malicious Office document, requiring user interaction but no additional authentication. Successful exploitation allows an attacker to overwrite heap memory, achieve arbitrary code execution with the privileges of the user running Office, and fully compromise the affected system. Patches are available from Microsoft.
Affected products
- Microsoft Office <UNKNOWN>
Timeline
- 2026-08-11: disclosed