Executive brief
Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information over a network. An unauthorized attacker can exploit this flaw to extract data from the affected system without requiring authentication, potentially exposing confidential documents or user data.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing logic, allowing an attacker to read memory beyond the intended bounds of a buffer. The vulnerability is triggered when processing a specially crafted Word document, which can be delivered over the network without user authentication. An attacker can craft a malicious Word file that, when processed by the vulnerable Word application, causes the application to leak sensitive information from process memory. The flaw impacts the confidentiality of data but does not allow modification of data or denial of service. Microsoft has released security updates to patch this vulnerability.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed