Junglewise Threat Intelligence

CVE-2026-63515: Microsoft Office out-of-bounds read allows local code execution

CVE-2026-63515 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used suite of productivity applications including Word, Excel, and PowerPoint. An out-of-bounds memory read vulnerability allows an attacker with local access to execute malicious code with the privileges of the Office application user, potentially leading to data theft, system compromise, or lateral movement within a network.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Office that can be leveraged to achieve local code execution. The flaw allows an attacker with local system access to read memory beyond intended boundaries, potentially disclosing sensitive information or corrupting program state. Exploitation requires local access to the affected system. An attacker can craft a malicious Office document or exploit the vulnerability through direct interaction with the Office application to execute arbitrary code in the context of the user running Office.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats