Executive brief
Microsoft Office Word is widely used for document creation and editing across enterprises. A heap-based buffer overflow vulnerability allows attackers to execute arbitrary code on a user's system when opening a malicious document, potentially leading to unauthorized data access, system compromise, or lateral movement within a network.
Technical details
This vulnerability is a heap-based buffer overflow in Microsoft Office Word's document processing logic. The flaw can be exploited by sending a specially crafted document file to a user, triggering memory corruption during parsing. An attacker with network access can exploit this without requiring authentication or user interaction beyond opening the document. Successful exploitation results in arbitrary code execution with the privileges of the Word process, enabling data theft, malware installation, or further network compromise. A patch is expected to be available through Microsoft's security update channels.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed