Sceawere

Vulnerability Detail

CVE-2026-63521UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Out-of-Bounds Read Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:48.867Z",
  "pubdate": "2026-08-11T17:18:48.867Z",
  "executiveSummary": "An out-of-bounds read vulnerability exists within Microsoft Office Word, specifically affecting how the application processes maliciously crafted document structures. This security flaw enables an unauthorized, locally positioned attacker to achieve information disclosure, potentially exposing sensitive memory contents or local data assets. The vulnerability impacts Microsoft Office Word and poses a risk to confidentiality by allowing unauthorized read operations beyond allocated memory boundaries. Exploitation of this vulnerability requires the attacker to have local access to the target system and likely necessitates user interaction, such as tricking a victim into opening a specially crafted document file. The risk implications include the potential leakage of sensitive system memory or application data, which could assist an attacker in orchestrating subsequent, more advanced exploitation chains, such as bypassing memory randomization protections like ASLR. Because the flaw centers on improper bounds checking during data parsing, hardening focuses on maintaining updated software patches and exercising caution when opening untrusted files.",
  "technicalDetails": "The vulnerability is an out-of-bounds read flaw residing in the document parsing components of Microsoft Office Word. The root cause stems from insufficient bounds validation when the application reads and processes specific internal structures within a Word file. Specifically, when parsing maliciously crafted offsets or length specifiers embedded within the document format, the parser fails to adequately verify whether the referenced memory addresses fall within the legitimate, allocated buffer boundaries.\nThe vulnerable component is the parsing engine responsible for interpreting internal file formats within Microsoft Office Word. During the attack flow, an unauthorized local attacker crafts a malicious document designed to manipulate internal parsing routines. When the target user opens this file, Microsoft Office Word attempts to parse the corrupted or maliciously modified structures. Due to the lack of proper input validation and boundary checks, the application reads data from memory locations outside the intended buffer allocation.\nThis unauthorized read operation can capture adjacent memory contents, which may contain sensitive runtime data, stack details, or heap artifacts. Depending on the specific memory contents exposed during the read operation, the payload behavior facilitates local information disclosure. While the direct impact is limited to reading data rather than executing arbitrary code, the extracted information can be leveraged in post-exploitation phases to map process memory layouts or assist in identifying addresses needed for bypass techniques against exploit mitigations.\nRegarding authentication and exposure vectors, the vulnerability requires local execution capabilities. The attacker must either have local interactive access to the victim machine to place and execute the file or rely on social engineering vectors to deliver the crafted document to the user. No network exposure or remote exploitation vector is described in the input mechanism, classifying this primarily as a local disclosure vector. Privilege requirements are minimal for the execution phase, as standard user privileges are typically sufficient to open documents within Microsoft Office Word."
}
CVE-2026-63521: Microsoft Office Word Out-of-Bounds Read Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere