Sceawere

Vulnerability Detail

CVE-2026-64907UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-121: Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:51.733Z",
  "pubdate": "2026-08-11T17:18:51.733Z",
  "executiveSummary": "This vulnerability is classified as a stack-based buffer overflow affecting Microsoft Office Word. The security flaw allows an unauthorized attacker to achieve local code execution on target systems hosting the vulnerable software. The primary impact of successful exploitation includes arbitrary code execution within the context of the current user, potentially leading to a complete compromise of the local system integrity, confidentiality, and availability. The affected product is Microsoft Office Word, specifically involving components that process malicious file formats or memory structures. Risk implications are severe, as unauthorized local execution can be chained with other privilege escalation vectors to compromise the underlying operating system. Attacker capabilities require the ability to deliver a specially crafted payload to the victim machine, typically through local file access or user interaction such as opening a malicious document. Exploitation requirements mandate that the targeted user opens a malformed file using the vulnerable Microsoft Office Word application, triggering the memory corruption flaw during parsing operations without requiring prior authentication or elevated privileges.",
  "technicalDetails": "The vulnerability stems from a stack-based buffer overflow condition located within Microsoft Office Word. The root cause of the issue is inadequate bounds checking when processing input data or memory structures, allowing malicious or excessively large payloads to overwrite adjacent stack memory regions, including saved instruction pointers and frame pointers. The vulnerable component is responsible for parsing specific document elements within Microsoft Office Word. Exploitation occurs when an unauthorized attacker crafts a malicious file containing oversized input data designed to exceed the fixed-size stack buffer allocated by the application. When Microsoft Office Word parses this malformed structure, the lack of proper length validation results in a memory corruption condition as data overflows the boundaries of the local stack buffer. The attack flow initiates when the victim opens the malicious document locally. As the application attempts to read and process the embedded payload, the overflow condition corrupts the call stack. Upon function return, the instruction pointer is redirected to attacker-controlled memory containing shellcode or malicious executable instructions. Because the execution flow is hijacked within the security context of the user running Microsoft Office Word, the injected payload executes with standard user privileges. The vulnerability requires local access and user interaction to open the file, meaning network exposure is indirect unless combined with a vector that delivers the file to the local system. Post-exploitation impact includes localized code execution, potential persistence establishment, deployment of secondary payloads, and escalation of privileges if auxiliary kernel or application vulnerabilities are subsequently leveraged."
}
CVE-2026-64907: Microsoft Office Word Buffer Overflow (HIGH Severity, CVSS: 7.8) - Sceawere