Executive brief
Microsoft Office Word is widely used for document creation and editing across organizations. A heap-based buffer overflow vulnerability in Word allows an attacker to execute arbitrary code by sending a specially crafted document over the network, potentially compromising user systems and exposing sensitive business data.
Technical details
A heap-based buffer overflow exists in Microsoft Office Word that can be triggered by a specially crafted document. The vulnerability is reachable over the network without requiring user authentication to the affected system, though user interaction (opening a malicious document) is typically required. An attacker can exploit this flaw to achieve remote code execution with the privileges of the user running Word. The vulnerability has a CVSS score of 8.8, indicating high severity, though no active exploitation in the wild has been reported as of the publication date.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed