Junglewise Threat Intelligence

CVE-2026-78502: Microsoft Office Word out-of-bounds read information disclosure

CVE-2026-78502 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office Word contains an out-of-bounds memory read vulnerability that allows an attacker to disclose sensitive information over a network. When a user opens a specially crafted Word document, the vulnerability can be exploited to leak confidential data without requiring authentication or user interaction beyond opening the file.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing logic. The flaw occurs when the application processes specially crafted Word documents, allowing memory outside the intended buffer boundaries to be read and potentially leaked to an attacker. The vulnerability requires network delivery of a malicious document and user interaction to open the file. While the attack results in information disclosure only (no integrity or availability impact), the leaked data could include sensitive corporate information stored in memory. Microsoft has issued patches to address this issue.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats