Executive brief
Microsoft Office is a widely used productivity suite that processes documents and spreadsheets. A heap-based buffer overflow vulnerability in Office allows an attacker with local access to execute arbitrary code with the privileges of the user running the application, potentially leading to data theft, malware installation, or system compromise.
Technical details
A heap-based buffer overflow exists in Microsoft Office, allowing local code execution. The vulnerability is triggered through a maliciously crafted Office document; an attacker with local system access or who can trick a user into opening a malicious file can exploit this flaw to overwrite heap memory and execute arbitrary code. The attack requires user interaction (opening a document) and local or adjacent network access. No known active exploitation in the wild at the time of publication. Patches are expected to be available through Microsoft's regular security update cycle.
Affected products
- Microsoft Office
Timeline
- 2026-08-11: disclosed