Executive brief
Microsoft Office Word is a widely-used word processing application found in most corporate environments. This vulnerability allows an authorized attacker with local access to read sensitive information from memory that should not be accessible, potentially exposing confidential document content or system data.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Word that allows an authorized local attacker to disclose sensitive information. The vulnerability requires local system access and the attacker must be already authorized on the target system. By exploiting this flaw, an attacker can read memory regions outside the intended bounds of a data structure, potentially exposing confidential information from the application's memory space. The CVSS score of 5.0 indicates medium severity with limited impact scope.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed