Executive brief
Microsoft Office Word contains a stack-based buffer overflow vulnerability that allows an attacker to execute arbitrary code on a user's computer when processing a specially crafted document. This vulnerability can be exploited remotely if an attacker tricks a user into opening a malicious Word document, potentially leading to complete system compromise, data theft, or ransomware deployment.
Technical details
A stack-based buffer overflow exists in Microsoft Office Word's document parsing logic. The vulnerability allows an attacker to overwrite the stack with arbitrary data by crafting a malicious Office document that triggers unbounded buffer writes. The attack vector is network-based; exploitation requires user interaction (opening a malicious document). A successful exploit results in arbitrary code execution with the privileges of the user running Word. Patches are expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed