Executive brief
Microsoft Office Word is a widely-used word processing application deployed across organizations globally. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted document over a network, potentially leading to system compromise, data theft, or malware installation.
Technical details
The vulnerability is a heap-based buffer overflow in Microsoft Office Word's document parsing logic. An attacker can trigger the overflow by sending a specially crafted Word document to a victim; the victim simply needs to open the file for the vulnerability to be exploitable. The overflow permits arbitrary code execution with the privileges of the user running Word, making it a critical attack vector for network-based compromise. No user interaction beyond opening a document is required to trigger the flaw.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed