Junglewise Threat Intelligence

CVE-2026-63525: Microsoft Office Word numeric truncation integer overflow

CVE-2026-63525 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely used word processing application in enterprise and consumer environments. A numeric truncation error in Word could allow an attacker to execute arbitrary code locally on a user's system, potentially leading to unauthorized access, data theft, or malware installation.

Technical details

A numeric truncation error in Microsoft Office Word allows for integer overflow or memory corruption during parsing or processing of document data. The vulnerability requires local code execution capability and likely involves crafted document files that trigger the truncation flaw. An attacker can exploit this to achieve code execution with the privileges of the user running Word. Patches are expected to be available through Microsoft's standard security updates.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats