Executive brief
Microsoft Office Word contains a heap-based buffer overflow vulnerability that could allow a local attacker to read sensitive information from the application's memory. This poses a risk to users who open specially crafted Word documents, potentially exposing confidential data such as passwords, encryption keys, or other sensitive content stored in memory during document processing.
Technical details
A heap-based buffer overflow exists in Microsoft Office Word's document parsing logic. The vulnerability is triggered when processing a malformed Word document, causing a buffer overrun in heap memory. The attack requires local access and user interaction (opening a malicious document). An attacker can exploit this to read arbitrary data from the process's heap memory, potentially disclosing sensitive information. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-11: disclosed