Executive brief
Microsoft Office Word is a widely used document creation and editing application in enterprise and consumer environments. A stack-based buffer overflow vulnerability allows a remote attacker to execute arbitrary code on a user's system, potentially leading to data theft, system compromise, or lateral movement within a corporate network.
Technical details
A stack-based buffer overflow exists in Microsoft Office Word that can be exploited by sending a specially crafted document over the network. The vulnerability permits remote code execution without requiring user authentication or elevated privileges. Attack conditions involve the target opening a malicious Word document, after which an attacker can achieve arbitrary code execution with the privileges of the logged-in user. Patches or updates from Microsoft are typically available through Windows Update or manual download from the Microsoft Security Response Center.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed