Junglewise Threat Intelligence

CVE-2026-63530: Microsoft Office Word out-of-bounds read in local processing

CVE-2026-63530 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word contains an out-of-bounds read vulnerability that allows an attacker to access sensitive information stored in memory on a local system. An unauthorized attacker could exploit this flaw to read confidential data without proper authorization, potentially exposing customer documents or system information.

Technical details

This vulnerability is an out-of-bounds read in the Microsoft Office Word document processing engine. The flaw occurs during local document parsing when Word reads beyond the bounds of an allocated memory buffer, exposing adjacent memory contents. An attacker would need to trick a user into opening a specially crafted Word document to trigger the vulnerability. The out-of-bounds read allows disclosure of information in memory but does not enable code execution. A patch is expected from Microsoft's security update process.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats