Executive brief
Microsoft Office Word contains an off-by-one buffer handling error that allows a local attacker to read sensitive information from memory that should not be accessible. An attacker with local access could exploit this to disclose confidential documents or data cached in memory, potentially compromising user privacy and data security.
Technical details
An off-by-one error in Microsoft Office Word's buffer management allows out-of-bounds memory access during local processing. The vulnerability requires local access and does not require authentication or user interaction beyond normal document handling. An attacker can read adjacent memory regions to disclose information that would otherwise be protected, such as cached file content or sensitive data in memory. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed