Junglewise Threat Intelligence

CVE-2026-63519: Microsoft Office heap-based buffer overflow

CVE-2026-63519 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a suite of productivity applications widely used across enterprises and organizations for document creation, spreadsheets, and presentations. A heap-based buffer overflow vulnerability in Microsoft Office could allow a local attacker to execute arbitrary code with the privileges of the user running Office, potentially leading to data theft, malware installation, or system compromise.

Technical details

A heap-based buffer overflow exists in Microsoft Office that can be triggered through specially crafted input, allowing an attacker to overwrite heap memory and execute arbitrary code. The vulnerability requires local access to the affected system and interaction from a user (such as opening a malicious document). An attacker with local access can exploit this to achieve code execution in the context of the Office application user. Microsoft has released or is expected to release patches to address this vulnerability.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats