Executive brief
Microsoft Office Word contains an out-of-bounds memory read vulnerability that allows an attacker to disclose sensitive information over the network. An unauthorized user can exploit this flaw by sending a specially crafted document, potentially exposing confidential data without requiring authentication or user interaction.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Office Word's document parsing logic. An attacker with network access can send a malicious Office document that triggers an out-of-bounds memory read in Word's processing engine, allowing information disclosure. No authentication is required, and the attack vector is network-based. The vulnerability permits an attacker to read sensitive data from the affected process memory. Microsoft has released patches to address this issue.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed: CVE-2026-77911 published