Junglewise Threat Intelligence

CVE-2026-63531: Microsoft Office Word out-of-bounds read in local parsing

CVE-2026-63531 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word is a widely-used document editor deployed across enterprises and consumer devices. An out-of-bounds read vulnerability could allow an attacker with local access to craft a malicious document that, when opened, exposes sensitive information from the application's memory (such as passwords, encryption keys, or document contents). This could lead to information disclosure and potential credential compromise.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Office Word's document parsing logic. The vulnerability occurs during local file processing when Word reads memory beyond the allocated buffer boundaries while parsing a specially crafted document. The attack vector is local and requires user interaction—a victim must open a malicious Office document. An attacker can exploit this to read sensitive information from Word's process memory. The vulnerability is tracked as CVE-2026-63531 with a CVSS score of 5.5 (medium severity); patch availability depends on Microsoft's release cycle.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-08-11: disclosed

References

Related threats