Executive brief
Microsoft Office Word is a widely used document editing application in business and enterprise environments. A stack-based buffer overflow vulnerability allows attackers to execute arbitrary code on a user's computer over the network, potentially leading to data theft, malware installation, or complete system compromise. This could enable attackers to gain unauthorized access to sensitive documents and corporate networks.
Technical details
The vulnerability is a stack-based buffer overflow in Microsoft Office Word that can be triggered over a network. The root cause involves improper memory handling when processing specially crafted input. The attack requires network connectivity and likely involves user interaction (opening a malicious document or network-accessed file). Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Word. Microsoft has released patches to address this vulnerability.
Affected products
- Microsoft Office Word <UNKNOWN>
Timeline
- 2026-09-08: disclosed