Executive brief
Microsoft Office Word contains a double free memory vulnerability that could allow an attacker to execute arbitrary code on a user's computer by sending a specially crafted Word document over the network. Exploitation could lead to unauthorized access to sensitive documents, theft of credentials, or deployment of malware without requiring any user interaction beyond opening the file.
Technical details
A double free vulnerability exists in Microsoft Office Word's document parsing logic, where the same memory region is freed multiple times during the processing of specially crafted documents. The vulnerability is triggered when Word processes a malicious .docx or similar Office document sent over a network. An attacker can exploit this memory corruption to achieve arbitrary code execution in the context of the Office application. No user authentication is required beyond normal file opening; the attack vector is network-based. A fix is expected to be available through Microsoft's security updates.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed