Junglewise Threat Intelligence

CVE-2026-69719: Microsoft Office Word buffer over-read in document parsing

CVE-2026-69719 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word processes document files and is widely used for creating and editing business documents. A buffer over-read vulnerability could allow an attacker to craft a malicious document that, when opened, exposes sensitive information from the application's memory. This could lead to disclosure of confidential data such as passwords, cryptographic keys, or other sensitive information residing in adjacent memory locations.

Technical details

The vulnerability is a buffer over-read in Microsoft Office Word's document parsing logic, which allows an attacker to read data beyond the intended memory boundaries. The vulnerability can be triggered by processing a specially crafted Office document; no authentication is required, but user interaction (opening a document) is necessary. An attacker can exploit this to leak sensitive data from the Word process memory over the network if the application sends the data to a remote location or the attacker has local access to the leaked information. A patch is available from Microsoft Security Response Center.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats