Executive brief
Microsoft Office is a widely-used productivity suite for creating and editing documents, spreadsheets, and presentations. A heap-based buffer overflow vulnerability allows attackers to execute arbitrary code on affected systems through a network attack, potentially leading to complete system compromise, data theft, or malware installation.
Technical details
This is a heap-based buffer overflow vulnerability in Microsoft Office that allows remote code execution over a network. The vulnerability likely stems from improper bounds checking in memory allocation within the Office parsing or document processing components. The attack vector is network-based, requiring no special authentication or user interaction beyond opening a malicious document or interacting with a compromised service. An attacker can exploit this to execute arbitrary code with the privileges of the affected Office process, potentially leading to system compromise. Microsoft has issued security updates to address this vulnerability.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed