Description
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is a buffer over-read in Microsoft Office Word that enables an unauthorized local attacker to read memory contents from the application process. This can lead to the disclosure of sensitive data such as passwords, encryption keys, or personal information that resides in memory at the time of exploitation. The weakness is characterized as an Improper Handling of Buffer Boundaries (CWE‑126) and can potentially compromise confidentiality for the affected user or organization, though it does not directly affect the broader system integrity or availability.

Affected Systems

Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016 are the documented targets of this flaw. No specific version numbers are disclosed in the available data, and the advisory does not enumerate affected build numbers beyond the product families.

Risk and Exploitability

With a CVSS score of 5.5 the issue is considered medium severity. The exploit probability is not quantified (EPSS data is missing) and the vulnerability is not currently listed in CISA KEV, suggesting a relatively low likelihood of large‑scale exploitation. However, as the vulnerability requires local authorization and allows memory disclosure, it still poses a tangible risk to confidential data if an attacker can gain local file or user access. The likely attack vector is local execution, potentially via a specially crafted document or malicious macro that triggers the over‑read during normal Word usage.

Generated by OpenCVE AI on September 9, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Office update that patches CVE‑2026‑83949, as advertised in the Microsoft Security Response Center.
  • Apply any cumulative roll‑up updates that include this correction to ensure the vulnerable buffer handling is replaced.
  • Limit local execution of Word for untrusted documents by enforcing restricted user accounts or disabling automatic loading of content that could trigger the buffer over‑read.

Generated by OpenCVE AI on September 9, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft word
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft word

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Word Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft word 2016
Weaknesses CWE-126
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:01.690Z

Reserved: 2026-08-31T23:40:59.641Z

Link: CVE-2026-83949

cve-icon Vulnrichment

Updated: 2026-09-08T19:57:04.279Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:05.273

Modified: 2026-09-08T20:44:11.103

Link: CVE-2026-83949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:45:15Z

Weaknesses