Executive brief
Microsoft Office contains a heap-based buffer overflow vulnerability that allows an attacker to execute arbitrary code on a user's computer. Exploitation typically requires local access or a user to open a specially crafted file, but successful exploitation could lead to complete system compromise, including theft of sensitive documents and financial data.
Technical details
A heap-based buffer overflow exists in Microsoft Office, triggered during memory allocation and write operations when processing certain input. The vulnerability is reachable via file parsing logic—typically when a user opens a malicious Office document. An attacker with local system access or the ability to deliver a crafted file to a target user can overflow the heap buffer, overwriting adjacent memory structures and achieving arbitrary code execution in the context of the Office application. No authentication is required once the file is opened. Patches are expected from Microsoft's regular security update cycle.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed