Executive brief
Microsoft Word, a widely used word processing application, contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code on a victim's computer when the user opens a specially crafted document. This vulnerability can be exploited remotely without any user credentials, enabling attackers to take full control of affected systems and potentially steal sensitive data or install malware.
Technical details
The vulnerability is a heap-based buffer overflow in Microsoft Word's document parsing logic. An attacker can craft a malicious Word document that triggers the overflow when processed, allowing arbitrary code execution with the privileges of the user running Word. The attack vector is network-based through document delivery, with the primary precondition being user interaction (opening the malicious file). No authentication is required. A patch is expected from Microsoft; consult the Microsoft Security Response Center for availability and guidance.
Affected products
- Microsoft Word
Timeline
- 2026-09-08: disclosed