Executive brief
Microsoft Office Word contains an input validation flaw that allows an attacker to disclose sensitive information over the network without authorization. An attacker could potentially extract confidential data from documents processed by Word, impacting the confidentiality of user information and potentially exposing business-critical content.
Technical details
The vulnerability stems from improper input validation in Microsoft Office Word's document processing logic. An attacker on the network can exploit this flaw to read sensitive information from Word documents without proper authorization. The exact attack vector and preconditions are not fully detailed in the available advisory text, but the network-based nature of the vulnerability suggests the attacker may not require local access or direct user interaction. A security update has been released by Microsoft to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-08-20: disclosed