Junglewise Threat Intelligence

CVE-2026-80079: Microsoft Office Word out-of-bounds read information disclosure

CVE-2026-80079 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information over a network. An attacker exploiting this flaw could extract confidential data from Word documents or the application's memory without requiring special privileges. This poses a risk to organizations handling sensitive documents through Word.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Word's document processing logic. The flaw allows an attacker to read memory beyond intended boundaries when processing specially crafted Word documents, leading to information disclosure. The vulnerability is reachable over the network and does not require user authentication, though it may require the victim to open a malicious document. An attacker can exploit this to extract sensitive data such as document contents or application memory. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats