Junglewise Threat Intelligence

CVE-2026-78522: Microsoft Office Word out-of-bounds read information disclosure

CVE-2026-78522 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information over a network. An unauthorized attacker could exploit this flaw to extract confidential data from Word documents or the application's memory. This poses a risk to organizations using Word for handling sensitive documents, potentially exposing business information, customer data, or other confidential content.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Office Word that enables information disclosure. An attacker can trigger the out-of-bounds read condition by sending a specially crafted input over the network, without requiring authentication. When exploited, the vulnerability allows reading memory contents beyond the intended bounds, potentially disclosing sensitive information from the Word process memory or document content. The attack vector is network-based, making it remotely exploitable. A patch or security update from Microsoft is expected to address this issue.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats