Executive brief
Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information over a network. An attacker with network access to a system running the affected Word version could exploit this to extract confidential data without authentication, compromising document privacy and potentially exposing business-critical information.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing logic. The vulnerability allows an attacker to craft a malicious document that, when opened or processed, triggers memory access beyond allocated buffer boundaries, leading to information disclosure. The attack vector is network-based and requires no user interaction beyond opening a file. An attacker can retrieve sensitive data from Word process memory without requiring authentication. A patch has been released by Microsoft as part of their standard security update process.
Affected products
- Microsoft Office Word <UNKNOWN>
Timeline
- 2026-09-08: disclosed