Junglewise Threat Intelligence

CVE-2026-69556: Microsoft Office Word heap-based buffer overflow

CVE-2026-69556 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used document editing application. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted Office document over the network. Exploitation requires no user privileges but may require the victim to open a malicious file.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word's document parsing logic. The vulnerability is triggered when Word processes a specially crafted document with malformed content, causing a buffer overwrite on the heap. The attack vector is network-based: an attacker can deliver a malicious Office document via email, file sharing, or web download. No authentication is required. Successful exploitation grants arbitrary code execution in the context of the Word process, potentially leading to system compromise. A patch is available from Microsoft.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats