Junglewise Threat Intelligence

CVE-2026-69734: Microsoft Office Word integer overflow allows information disclosure

CVE-2026-69734 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used document editing application. An integer overflow vulnerability in Word could allow an attacker to trigger memory corruption and extract sensitive information from affected systems over a network, potentially exposing confidential documents or user data.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft Office Word's processing of document files. The vulnerability occurs when Word handles specially crafted input that causes integer arithmetic to overflow, leading to memory corruption. An attacker can exploit this by sending or tricking a user into opening a malicious Word document over a network. The vulnerability allows information disclosure; while no remote code execution is indicated, the memory corruption can be leveraged to read sensitive data from the application's memory space.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats