Executive brief
Microsoft Office is a suite of productivity applications widely used in enterprises for document creation and collaboration. A heap-based buffer overflow vulnerability allows attackers to disclose sensitive information by sending specially crafted files over a network, potentially exposing corporate data without requiring user credentials or permissions.
Technical details
A heap-based buffer overflow exists in Microsoft Office when processing malformed input. An attacker can exploit this vulnerability by crafting and delivering a malicious file over the network that triggers the overflow condition in memory, leading to information disclosure. The vulnerability is remotely exploitable over a network vector and does not require authentication or special user interaction. While no active exploitation in the wild has been reported, the ability to leak sensitive data from memory makes this a notable risk for organizations.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed