Executive brief
Microsoft Office contains a vulnerability where uninitialized resources can be accessed, potentially allowing an attacker on the network to view sensitive information stored in or processed by Office documents. This could expose confidential business data, personal information, or other sensitive content without requiring the attacker to have legitimate access to the system.
Technical details
This vulnerability is classified as a use of uninitialized resource issue in Microsoft Office. An attacker on the network can trigger the vulnerability to disclose sensitive information from memory or document contents. The attack requires network connectivity to the affected Office application or system. No exploitation in the wild has been reported as of the advisory date. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed