Junglewise Threat Intelligence

CVE-2026-63517: Microsoft Office out-of-bounds read

CVE-2026-63517 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used productivity suite for creating and editing documents, spreadsheets, and presentations. An out-of-bounds read vulnerability allows an attacker with local access to read sensitive data from memory that should not be accessible, potentially exposing confidential information such as document contents or cached credentials.

Technical details

This vulnerability is an out-of-bounds read (CWE-125) in Microsoft Office that occurs when the application attempts to access memory beyond the bounds of an allocated buffer. The flaw requires local attack vector, meaning the attacker must have access to the affected system. A successful exploit allows unauthorized disclosure of information resident in memory, but does not permit code execution or privilege escalation. The specific vulnerable component and triggering mechanism are not detailed in the advisory. A patch is expected to be available through Microsoft's standard security update process.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats