Junglewise Threat Intelligence

CVE-2026-63521: Microsoft Office Word out-of-bounds read

CVE-2026-63521 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used word processing application in enterprise and consumer environments. An out-of-bounds read vulnerability allows an attacker with local access to the system to disclose sensitive information from memory, potentially exposing confidential documents, cached data, or other sensitive content.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Office Word's memory handling. The attack requires local access to the affected system. Successful exploitation allows an attacker to read memory outside allocated bounds, potentially disclosing sensitive information such as document content or other protected data. The vulnerability has a CVSS v3.1 score of 5.5, reflecting low confidentiality impact with local attack vector requirements. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats