Junglewise Threat Intelligence

CVE-2026-70105: Microsoft Office Word improper input validation

CVE-2026-70105 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word contains an input validation flaw that allows an attacker to disclose sensitive information over the network without authorization. An attacker could potentially extract confidential data from documents processed by Word, impacting the confidentiality of user information and potentially exposing business-critical content.

Technical details

The vulnerability stems from improper input validation in Microsoft Office Word's document processing logic. An attacker on the network can exploit this flaw to read sensitive information from Word documents without proper authorization. The exact attack vector and preconditions are not fully detailed in the available advisory text, but the network-based nature of the vulnerability suggests the attacker may not require local access or direct user interaction. A security update has been released by Microsoft to address this issue.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-20: disclosed

References

Related threats