Executive brief
Microsoft Office Publisher is a desktop application used to create and distribute marketing materials and publications. A flaw in how it processes document files allows an attacker to craft a malicious document that executes arbitrary code on a user's computer when opened. An attacker can distribute this document via email or website to compromise systems and steal data or install malware.
Technical details
The vulnerability is a deserialization of untrusted data flaw in Microsoft Office Publisher. When a user opens a specially crafted document file, the application deserializes attacker-controlled data without proper validation, allowing arbitrary code execution. The attack vector is network-based (via document delivery), but requires user interaction to open the malicious file. An authenticated user is not required. A successful exploit grants the attacker code execution in the context of the user running Publisher, potentially allowing full system compromise.
Affected products
- Microsoft Office Publisher
Timeline
- 2026-09-08: disclosed