Sceawere

Vulnerability Detail

CVE-2026-63528UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Out-of-Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:49.660Z",
  "pubdate": "2026-08-11T17:18:49.660Z",
  "executiveSummary": "An out-of-bounds read vulnerability exists in Microsoft Office Word, which enables an unauthorized local attacker to disclose sensitive information. The flaw specifically resides within the document parsing and memory management components of Microsoft Office Word, affecting confidentiality by allowing unauthorized access to adjacent memory regions. Risk implications center on the potential exposure of sensitive data stored within the process memory space, which could be leveraged to facilitate subsequent, more advanced exploitation chains such as bypassing mitigation controls like Address Space Layout Randomization. Attacker capabilities are constrained to local information disclosure, meaning the adversary must already possess execution capabilities or deliver a specially crafted document locally on the target system. Exploitation requirements mandate that the target user or system opens a maliciously structured Word document designed to trigger the out-of-bounds read condition during parsing operations.",
  "technicalDetails": "The vulnerability is fundamentally rooted in an out-of-bounds read flaw within the memory handling and parsing engine of Microsoft Office Word. When processing a maliciously crafted document, the application fails to adequately validate boundary conditions and size parameters associated with specific file structures or internal parsing buffers. This insufficient bounds checking causes the parsing engine to read data past the allocated buffer boundaries into adjacent heap or stack memory locations.\nThe attack flow initiates when a user opens a specially crafted file using a vulnerable version of Microsoft Office Word. As the application parses the malicious elements embedded within the file structure, the vulnerable component attempts to read data based on corrupted or manipulated length indicators supplied by the input file. Instead of terminating or safely handling the anomalous input, the parsing function executes a read operation outside the legitimate memory boundaries of the designated buffer.\nThe vulnerable component involves the document parsing and rendering logic responsible for interpreting specific internal file formats within Microsoft Office Word. The affected versions encompass the standard Microsoft Office Word iterations specified in the operational environment. Regarding authentication and privilege requirements, the attack operates locally and does not inherently require elevated privileges or pre-existing authentication within the application, although local execution context on the target host is necessary.\nNetwork exposure for this specific vector is limited, as the vulnerability manifests locally during file ingestion and parsing rather than via a remote service listener. Payload behavior during exploitation does not involve arbitrary code execution or modification of system state; rather, it results in the silent retrieval of unauthorized memory contents. The post-exploitation impact is strictly confined to local information disclosure, wherein the exposed memory contents may contain residual data, cryptographic keys, heap addresses, or other sensitive user and system artifacts that can aid an attacker in mapping the target environment or staging further attacks."
}
CVE-2026-63528: Microsoft Office Word Out-of-Bounds Read (MEDIUM Severity, CVSS: 5.5) - Sceawere