Junglewise Threat Intelligence

CVE-2026-68843: Microsoft Office Word use-after-free information disclosure

CVE-2026-68843 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word contains a use-after-free vulnerability that allows an authorized user to access sensitive information stored in memory. An attacker with legitimate access to Word could exploit this flaw to read confidential documents or data that should not be accessible, potentially compromising document confidentiality and exposing business-sensitive information.

Technical details

A use-after-free vulnerability exists in Microsoft Office Word where freed memory is accessed after deallocation. The vulnerability is triggered during authorized local operation, requiring an attacker to have valid access to the Word application. Successful exploitation allows information disclosure by reading sensitive data from deallocated memory regions. The attack vector is local and does not require network access or privilege escalation beyond normal user permissions. Microsoft has released or planned a security patch to address this issue.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats