Sceawere

Vulnerability Detail

CVE-2026-64917UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Word Out-Of-Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-125: Out-of-bounds Read
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:53.050Z",
  "pubdate": "2026-08-11T17:18:53.050Z",
  "executiveSummary": "An out-of-bounds read vulnerability exists in Microsoft Office Word, categorized as an information disclosure flaw. The vulnerability allows an unauthorized local attacker to access sensitive system memory or data contents that should otherwise be restricted.\nThe affected product is Microsoft Office Word. The primary risk implication of this vulnerability is the unauthorized exposure of confidential information residing in memory, which could potentially be leveraged by an attacker to facilitate more complex, multi-stage attacks or to harvest sensitive credentials and data.\nAttacker capabilities are constrained to local access, meaning the threat actor must already have execution privileges or local access to the target system to interact with the vulnerable application instance. Exploitation requirements involve the targeted processing of a specially crafted file or input by a user within the Microsoft Office Word environment, triggering the memory disclosure condition without requiring elevated administrative privileges.",
  "technicalDetails": "The root cause of the vulnerability is an out-of-bounds read condition residing within the memory management and parsing logic of Microsoft Office Word. Specifically, the application fails to properly validate the boundaries and size parameters of specific data structures or input streams during the parsing of document formats. When Microsoft Office Word processes a malformed or maliciously crafted structure, it reads past the allocated buffer boundary into adjacent memory regions.\nThe vulnerable component involves the internal document parser responsible for interpreting specific object attributes or layout records within Microsoft Office Word. Because the software lacks adequate bounds-checking mechanisms prior to memory read operations, arbitrary or adjacent memory contents are accessed and potentially reflected back through application behavior or logs.\nThe attack flow proceeds as follows: First, an unauthorized local attacker crafts a malicious file containing manipulated structural descriptors designed to trigger the out-of-bounds read condition. Second, the victim opens this crafted file using a vulnerable version of Microsoft Office Word. Third, as the application parses the malformed structures, the internal parsing routines read data beyond the designated buffer boundaries. Finally, the out-of-bounds read exposes sensitive data contained in adjacent memory spaces, which can then be captured or inferred by the attacker.\nRegarding environmental and access constraints, the vulnerability requires local execution context or user interaction to open the malicious file. Network exposure is direct only if the file is delivered via remote shares or web vectors, but the exploitation vector itself manifests locally during document rendering. Privilege requirements are minimal, as standard unprivileged users can trigger the parsing logic. No authentication is required beyond local system access or the ability to supply the input file to the victim application.\nThe post-exploitation impact centers primarily on local information disclosure. By reading arbitrary memory locations, an adversary may acquire sensitive data structures, including heap memory contents, cryptographic keys, user credentials, or internal application state information. This harvested data can subsequently be utilized to bypass secondary defenses or orchestrate privilege escalation chains."
}
CVE-2026-64917: Microsoft Office Word Out-Of-Bounds Read (MEDIUM Severity, CVSS: 5.5) - Sceawere