Executive brief
Microsoft Office Word contains an improper null termination vulnerability that allows a local attacker to read sensitive information from the application's memory. An attacker with local access to a system where Word is running could exploit this to access confidential documents or data without authorization.
Technical details
The vulnerability is caused by improper null termination handling in Microsoft Office Word's string or buffer processing logic. This allows an attacker with local access to disclose information from memory. The attack vector is local, meaning the attacker must have access to the target machine. This is an information disclosure vulnerability (CWE-126 or related), not a remote code execution flaw. A patch is expected to be available from Microsoft.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed