Sceawere

Vulnerability Detail

CVE-2026-63517UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Out-of-Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:46.657Z",
  "pubdate": "2026-08-11T17:18:46.657Z",
  "executiveSummary": "An out-of-bounds read vulnerability exists within Microsoft Office, which can be exploited by an unauthorized, local attacker to achieve unauthorized information disclosure.\nThe vulnerability affects Microsoft Office products and stems from improper handling of memory bounds during the parsing of specially crafted files or data structures.\nIf successfully exploited, the flaw permits an attacker to read sensitive memory contents from the host system, potentially exposing confidential data, cryptographic keys, or internal application states.\nExploitation requires the attacker to have local access to the target system, often involving tricking a user into opening a malicious file or leveraging pre-existing local execution capabilities.\nThe risk implication centers on the compromise of data confidentiality, as unauthorized memory exposure can facilitate further targeted attacks or privilege escalation chains.\nNo specific elevated privileges are inherently required for the local attacker beyond the ability to execute code or interact with the vulnerable Microsoft Office component.",
  "technicalDetails": "The vulnerability is an out-of-bounds read flaw localized within the data parsing and memory management routines of Microsoft Office.\nThe root cause lies in the failure of the application to properly validate the length parameters and boundary constraints of input data streams before performing memory read operations.\nWhen Microsoft Office processes a malformed or maliciously constructed file, the internal parser miscalculates the required buffer size or offset, resulting in read operations that exceed the allocated buffer boundaries.\nAttack execution typically begins when a local user opens a specially crafted document designed to trigger the out-of-bounds condition within the vulnerable component.\nUpon parsing the malicious file structure, the vulnerable function attempts to read data from memory addresses outside the legitimate bounds of the allocated buffer.\nThis unauthorized read operation allows the extraction of adjacent memory contents, which may contain sensitive runtime data, user information, or system artifacts.\nThe affected component involves the file parsing and rendering subsystems of Microsoft Office.\nAuthentication is not required for the local attack vector, and the attacker operates within the context of the locally executed process or user session.\nThe network exposure is strictly local, requiring local interaction or prior local file placement to initiate the parsing process.\nPost-exploitation impact is primarily characterized by local information disclosure, wherein the leaked memory contents can be exfiltrated or analyzed by the attacker to map memory layouts, bypass security controls like ASLR in subsequent exploits, or harvest credentials and sensitive application data."
}
CVE-2026-63517: Microsoft Office Out-of-Bounds Read (MEDIUM Severity, CVSS: 5.5) - Sceawere