Sceawere

Vulnerability Detail

CVE-2026-63527UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-121: Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:49.530Z",
  "pubdate": "2026-08-11T17:18:49.530Z",
  "executiveSummary": "This vulnerability is classified as a stack-based buffer overflow affecting Microsoft Office Word. The flaw enables an unauthorized, local attacker to achieve arbitrary code execution on target systems. The primary impact of successful exploitation includes complete system compromise within the security context of the currently logged-in user, potentially leading to unauthorized data access, modification, or system destabilization. Affected systems comprise targeted installations of Microsoft Office Word processing vulnerable document formats. The risk implications are severe due to the prevalence of document-based attack vectors frequently utilized in targeted campaigns and phishing operations. Attacker capabilities involve executing arbitrary malicious payloads locally upon successful interaction with a maliciously crafted file. Exploitation requirements mandate that the victim opens a specially crafted file supplied by the adversary, meaning user interaction is typically required to trigger the underlying memory corruption condition.",
  "technicalDetails": "The vulnerability resides in the memory management handling of Microsoft Office Word when parsing specific structured data fields within document files. Specifically, a stack-based buffer overflow occurs due to insufficient bounds checking when processing input data, allowing malicious input to exceed the allocated boundaries of a stack-based buffer. This memory corruption condition overwrites adjacent stack frames, including critical control data such as saved frame pointers and return addresses. The vulnerable component is the file parsing and rendering engine responsible for interpreting legacy or complex document formats within Microsoft Office Word. Exploitation requires the attacker to deliver a malformed document file to the target system via local transfer or external delivery mechanisms. The attack flow commences when the user opens the malicious file using an unpatched instance of Microsoft Office Word. As the application attempts to parse the malicious data structure, the oversized input overflows the destination buffer on the stack. By carefully crafting the payload, an attacker can manipulate the overwritten return address to redirect execution flow to shellcode embedded within the stack or heap, assuming mitigation bypasses are addressed. Authentication and network exposure are not direct prerequisites for exploitation, as the vector is local file handling; however, remote delivery often precedes local execution via social engineering or spear-phishing campaigns. Privilege requirements are minimal, as the malicious code executes with the standard user privileges assigned to the local application process. Post-exploitation impact encompasses unauthorized execution of system binaries, persistence establishment, lateral movement within the network environment, and complete integrity and confidentiality compromise of user-accessible data."
}
CVE-2026-63527: Microsoft Office Word Buffer Overflow (HIGH Severity, CVSS: 7.8) - Sceawere