Junglewise Threat Intelligence

CVE-2026-63533: Microsoft Office heap-based buffer overflow

CVE-2026-63533 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a suite of productivity applications used by millions of organizations for document creation, spreadsheets, and presentations. A heap-based buffer overflow vulnerability allows attackers to execute malicious code locally on systems running affected Office versions, potentially compromising sensitive documents and enabling unauthorized access to user data.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office that allows local code execution. The vulnerability is triggered when processing specially crafted Office documents, enabling an attacker to overwrite heap memory and gain arbitrary code execution with the privileges of the user running Office. Exploitation requires user interaction (opening a malicious document) but does not require elevated privileges. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats