Junglewise Threat Intelligence

CVE-2026-63528: Microsoft Office Word out-of-bounds read in document parsing

CVE-2026-63528 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word contains a memory reading flaw that allows an attacker to extract sensitive information from a user's system by crafting a malicious document. When a user opens the compromised document, the vulnerability exposes data that could include passwords, encryption keys, or other confidential information stored in memory.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Office Word's document parsing engine, allowing an attacker to read memory beyond allocated buffer boundaries. The vulnerability is triggered when Word processes a specially crafted document file, and requires user interaction (opening the malicious file). The attack vector is local; the attacker cannot exploit this remotely. A successful exploit results in information disclosure of sensitive data resident in process memory, without the ability to modify data or cause denial of service. Patches from Microsoft are available through the Security Update Guide.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References

Related threats