Executive brief
Microsoft Office is a suite of productivity applications used across enterprises to create and edit documents, spreadsheets, and presentations. A heap-based buffer overflow vulnerability in Office could allow an attacker to execute arbitrary code on an affected system simply by sending a specially crafted file over the network, potentially leading to data theft, system compromise, or lateral movement through an organization.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office that does not properly validate buffer boundaries during memory operations. The vulnerability can be triggered remotely when a user opens or processes a malicious Office document, without requiring authentication. An attacker can craft a specially formatted file that, when processed by Office, overflows a heap buffer and overwrites adjacent memory, achieving code execution with the privileges of the user running Office. A patch is expected from Microsoft through their regular security update cycle.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed