Junglewise Threat Intelligence

CVE-2026-80088: Microsoft Office Word out-of-bounds read information disclosure

CVE-2026-80088 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office Word contains an out-of-bounds read vulnerability that could allow an attacker to remotely read sensitive information from memory. An attacker would need to craft a malicious Word document and send it to a target user; opening the file could leak confidential data from the affected system.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing logic, permitting unauthorized information disclosure. The vulnerability is triggered when Word processes a specially crafted document, reading memory beyond the intended buffer boundaries. An attacker can exploit this remotely by distributing a malicious Word file; user interaction (opening the document) is required for exploitation. Successful exploitation leads to disclosure of sensitive information from process memory, though arbitrary code execution is not possible with this flaw alone. A patch has been released by Microsoft.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats