Executive brief
Microsoft Office contains an out-of-bounds read vulnerability that allows a local attacker to read sensitive information from memory. An attacker with local access to a system running vulnerable Office software could exploit this to access confidential data, such as credentials or document contents, without authorization.
Technical details
This vulnerability is an out-of-bounds read in Microsoft Office, a memory safety issue where the application reads data beyond the bounds of an allocated buffer. The vulnerability requires local access to the affected system and allows an unauthenticated attacker to disclose information resident in memory. The attack vector is local, meaning the attacker must have code execution capability or local system access. Microsoft has released patches to address this issue as indicated by the CVE disclosure.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed