Sceawere

Vulnerability Detail

CVE-2026-63515UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Out-of-Bounds Read

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:46.357Z",
  "pubdate": "2026-08-11T17:18:46.357Z",
  "executiveSummary": "This vulnerability is classified as an out-of-bounds read affecting Microsoft Office. The primary impact of this security flaw includes local code execution, which compromises the confidentiality, integrity, and availability of the host system. The affected systems encompass vulnerable installations of Microsoft Office. The risk implications are severe, as successful exploitation enables an unauthorized local attacker to execute arbitrary code within the context of the current user. Attacker capabilities require the local execution of malicious payloads or interaction with a specially crafted file. Exploitation requirements mandate that the target user opens a malicious document or file using an unpatched instance of the vulnerable software, thereby triggering the memory read error and subsequent execution vector.",
  "technicalDetails": "The root cause of the vulnerability stems from improper bounds checking within the memory parsing routines of Microsoft Office. When the affected software processes a malformed or maliciously crafted file, it fails to properly validate input length parameters prior to executing memory read operations. This lack of bounds enforcement leads directly to an out-of-bounds read condition, where the application attempts to read data from memory locations outside the designated buffer boundaries.\nThe vulnerable component resides within the core file parsing and rendering architecture of Microsoft Office. Exploitation occurs step-by-step as follows: First, the unauthorized attacker crafts a malicious file containing manipulated structural metadata designed to deceive the parsing engine regarding data lengths and offsets. Second, the victim opens the crafted file locally using the vulnerable Microsoft Office application. Third, during the document parsing phase, the vulnerable component reads memory past the allocated buffer bounds. Fourth, the anomalous memory state or exposed pointer leakage is leveraged to manipulate control flow or stage subsequent memory corruption primitives.\nThe attack vector operates locally, requiring no network exposure for initial access, although social engineering is typically required to deliver the file to the victim. Authentication requirements are nonexistent as the execution relies entirely on local file handling. Privilege requirements are limited to standard user privileges, meaning the injected code executes with the rights of the locally logged-in user. The post-exploitation impact includes localized code execution, potential escalation of privileges if chaining additional vulnerabilities, and unauthorized access to sensitive data residing in adjacent memory regions."
}
CVE-2026-63515: Microsoft Office Out-of-Bounds Read (HIGH Severity, CVSS: 7.8) - Sceawere