Junglewise Threat Intelligence

CVE-2026-63518: Microsoft Office Word heap-based buffer overflow

CVE-2026-63518 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used document creation and editing application. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code locally on a system running a vulnerable version of Word, potentially compromising sensitive documents and enabling system takeover.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word's document processing logic. The vulnerability is triggered when Word processes a specially crafted document, causing the application to write data beyond the bounds of an allocated heap buffer. An attacker must trick a user into opening a malicious document to exploit this vulnerability; no network access is required. Successful exploitation grants the attacker arbitrary code execution with the privileges of the user running Word. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats