Junglewise Threat Intelligence

CVE-2026-83949: Microsoft Office Word buffer over-read

CVE-2026-83949 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Word is a widely-used document editing application. A buffer over-read vulnerability could allow an attacker with local access to read sensitive data from memory that Word has processed, potentially exposing confidential information contained in documents or system memory.

Technical details

A buffer over-read vulnerability exists in Microsoft Office Word, allowing out-of-bounds memory access during document processing. The vulnerability is triggered through local access and permits an attacker to read adjacent memory contents, potentially disclosing sensitive information. No network attack vector or user interaction is required beyond local access. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Word UNKNOWN

Timeline

  • 2026-09-08: disclosed

References

Related threats