Junglewise Threat Intelligence

CVE-2026-63524: Microsoft Office out-of-bounds read

CVE-2026-63524 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains an out-of-bounds read vulnerability that allows a local attacker to read sensitive information from memory. An attacker with local access to an affected system could exploit this flaw to extract data such as passwords, encryption keys, or other confidential information stored in the application's memory.

Technical details

The vulnerability is an out-of-bounds read condition in Microsoft Office that permits local information disclosure. The flaw is triggered when the application processes certain inputs without proper bounds checking, allowing an attacker to read adjacent memory regions. This requires local access to the system where Office is installed. The attacker can leverage this to extract sensitive data from the Office process memory. A patch has been released by Microsoft as indicated by the Security Update Guide reference.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats