Executive brief
Microsoft Office Word is a widely used document editing application in enterprise and consumer environments. A null pointer dereference vulnerability in Word allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted document over the network, potentially compromising sensitive data, stealing credentials, or establishing a persistent foothold for further attacks.
Technical details
A null pointer dereference vulnerability exists in Microsoft Office Word's document parsing logic, allowing remote code execution when a user opens a malicious Word document. The vulnerability is accessible over the network through document delivery mechanisms and does not require authentication or special user privileges beyond opening the document. An attacker can craft a malicious Office document that triggers unsafe memory access, leading to arbitrary code execution in the context of the Word application. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed