Heap-based buffer overflow in Microsoft Office for macOS and Microsoft Word - CVE-2026-66810
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to heap-based buffer overflow in Microsoft Office Word when parsing a crafted document. A remote attacker can trick the victim into opening a specially crafted file to disclose sensitive information.
The disclosed information may include portions of process memory. The Preview Pane is not an attack vector for this vulnerability.
Affected software
Microsoft Word
How to mitigate CVE-2026-66810
Microsoft Word - update to 16.0.5565.1000