Junglewise Threat Intelligence

CVE-2026-63513: Microsoft Office heap-based buffer overflow

CVE-2026-63513 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used productivity suite that processes documents, spreadsheets, and presentations. A heap-based buffer overflow vulnerability in the software allows an attacker to execute arbitrary code on a user's system with local access, potentially leading to data theft, system compromise, or malware installation.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office that allows arbitrary code execution. The vulnerability is triggered locally and requires no network access. An attacker with local access to the system or who can deliver a specially-crafted file to a user can exploit this flaw to execute code with the privileges of the Office application. Microsoft has released patches to address this vulnerability; users should apply the latest security updates promptly.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats