Junglewise Threat Intelligence

CVE-2026-78524: Microsoft Office out-of-bounds write in document handling

CVE-2026-78524 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office is a widely-used suite of productivity applications for document creation and editing. An out-of-bounds write vulnerability in Office's document processing could allow an attacker to execute arbitrary code on a user's computer when a malicious document is opened, potentially leading to data theft, system compromise, or ransomware installation.

Technical details

This is an out-of-bounds write vulnerability in Microsoft Office's document parsing logic. The vulnerability allows remote code execution when a specially crafted Office document is processed. An attacker can deliver the malicious document via email, web download, or file sharing, and if a user opens it, the attacker gains code execution in the context of the Office application. While not yet observed in active exploits in the wild, the high CVSS score (8.8) indicates significant severity and network-accessible attack vector. Microsoft has issued a security update to address this flaw.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats