Junglewise Threat Intelligence

CVE-2026-63529: Microsoft Office out-of-bounds read information disclosure

CVE-2026-63529 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains an out-of-bounds read vulnerability that could allow an attacker with local access to read sensitive information from the application's memory. An attacker exploiting this issue could potentially access confidential documents, credentials, or other sensitive data stored in memory without authorization.

Technical details

This vulnerability is an out-of-bounds read flaw in Microsoft Office where improper bounds checking allows reading memory beyond allocated buffers. The vulnerability requires local access to the affected system and does not require user interaction or authentication. An attacker can leverage this to read arbitrary data from the Office application's memory, potentially exposing sensitive information such as document content or credentials. Microsoft has issued patches to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats