Description
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local information disclosure
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read bug in Microsoft Office Word allows an authorized local attacker to read data from memory that should not be exposed, potentially revealing sensitive information such as passwords, cryptographic keys, or other confidential data. The vulnerability is classified as CWE‑125 and does not provide remote code execution or denial of service capabilities. The bug requires the attacker to have a user account on the affected machine and the ability to run Word normally.

Affected Systems

Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016 and their macOS counterparts. Version details are not specified; all recent releases of these products are likely vulnerable.

Risk and Exploitability

The CVSS score of 5 indicates medium overall severity, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires local authorization and does not provide an external attack vector, so the exploitation risk is moderate. The only documented fix is the Microsoft Office update that addresses CVE‑2026‑72976.

Generated by OpenCVE AI on September 9, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Office update that addresses CVE‑2026‑72976 by following the guidance on the Microsoft Update Center.
  • Reboot affected systems to ensure patched binaries are in use by all Office processes.
  • Restrict the ability of non‑trusted users to open Word documents or run Word as an authorized user, thereby limiting the potential for exploitation.

Generated by OpenCVE AI on September 9, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
Microsoft word
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft microsoft 365
Microsoft word

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
Title Microsoft Office Word Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:33.697Z

Reserved: 2026-08-10T18:36:42.030Z

Link: CVE-2026-72976

cve-icon Vulnrichment

Updated: 2026-09-08T20:05:32.945Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:23.877

Modified: 2026-09-17T20:18:09.163

Link: CVE-2026-72976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T07:45:15Z

Weaknesses