Executive brief
Microsoft Office Word is a widely-used document editor deployed across most organizations. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's system when they open a malicious document, potentially leading to data theft, malware installation, or lateral movement within a network.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office Word's document parsing logic. The vulnerability can be triggered by a specially crafted Office document sent over the network; no user authentication is required, though the user must open the malicious file. An attacker can exploit this to achieve remote code execution with the privileges of the user running Word. The vulnerability is classified as high-severity with a CVSS score of 8.8, and patches are available from Microsoft.
Affected products
- Microsoft Word
Timeline
- 2026-09-08: disclosed