Executive brief
Microsoft Office Word contains a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a user's computer through a specially crafted document. An attacker could exploit this remotely without user credentials, potentially leading to data theft, system compromise, or malware installation.
Technical details
A stack-based buffer overflow exists in Microsoft Office Word's document parsing logic. The vulnerability is triggered when Word processes a maliciously crafted document that causes an out-of-bounds write to the stack. The attack is network-reachable and requires user interaction (opening or previewing a malicious document). Successful exploitation allows code execution in the context of the user running Word. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed