Executive brief
Microsoft Office is a widely-used productivity suite for creating and editing documents, spreadsheets, and presentations. This vulnerability allows a remote attacker to read sensitive information from affected systems by exploiting a memory parsing flaw, potentially exposing confidential data such as document content or user credentials.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office's document parsing logic, allowing an attacker to access memory beyond allocated buffer boundaries. The vulnerability can be exploited over the network by sending a malicious Office document without requiring authentication or user interaction. Successful exploitation results in information disclosure, enabling attackers to exfiltrate sensitive data from affected systems. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed