Executive brief
Microsoft Office Word, a widely-used word processor for creating and editing documents, contains a memory reading vulnerability that could allow an unauthorized attacker to read sensitive data from the affected system's memory. An attacker with local access could exploit this flaw to disclose information that should remain confidential.
Technical details
This vulnerability is a buffer over-read flaw in Microsoft Office Word that permits reading beyond allocated memory boundaries. The issue is triggered locally and allows an attacker to access unintended memory regions, potentially disclosing sensitive information from the process memory. The attack vector requires local access to the affected machine. A patch is expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Office Word
Timeline
- 2026-09-08: disclosed