Junglewise Threat Intelligence

CVE-2026-69360: Microsoft Office Word heap-based buffer overflow

CVE-2026-69360 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used word processing application used by organizations for document creation and editing. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's computer, potentially compromising sensitive documents, enabling data theft, or establishing a foothold for further attacks on corporate networks.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word, allowing remote code execution when a user opens a maliciously crafted document. The vulnerability stems from improper bounds checking in memory allocation, enabling an attacker to overwrite heap memory and execute arbitrary code. The attack requires user interaction (opening a document) but does not require authentication. An attacker can achieve code execution with the privileges of the user running Word, potentially compromising the system and accessing sensitive data. Patches are expected to be available via Microsoft's regular security update channels.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats