Executive brief
Microsoft Office Word is a widely-used word processing application found in millions of PCs and business environments. A numeric truncation error in Word can be exploited by an attacker to execute arbitrary code on a user's computer, potentially leading to data theft, malware installation, or system compromise.
Technical details
A numeric truncation error in Microsoft Office Word's document parsing logic allows remote code execution. An attacker can craft a malicious Word document that, when opened by a victim, triggers the vulnerability through a network-accessible mechanism. The vulnerability permits unauthenticated remote code execution with no reported user interaction bypass requirement. No patch availability information is currently confirmed in the provided advisory text.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed