Executive brief
Microsoft Office contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information over a network. An attacker can exploit this flaw to access confidential data within Office documents or processes without proper authorization. This could expose customer data, trade secrets, or other sensitive business information to unauthorized parties.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office, allowing an attacker to read memory beyond intended boundaries. The vulnerability can be exploited remotely over a network, requiring no user authentication but likely requiring the victim to open a specially crafted file or interact with malicious content. A successful exploit permits information disclosure, enabling the attacker to extract sensitive data from Office processes. While not yet actively exploited in the wild, the public disclosure indicates patches are or will be available from Microsoft.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed