CVE Tools

CVE-2026-63524

Microsoft Office Information Disclosure Vulnerability

Published: Aug 11, 2026Updated: Aug 14, 2026 Sources: CVE List NVDCWE-125

Description

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

In plain language

AI Act now

CVE-2026-63524 is a Microsoft Office bug that can expose confidential information if someone with local access gets you to open a specially made Office file; most small businesses should patch, but it’s not an automatic internet threat.

Executive summary

CVE-2026-63524 is a Microsoft Office information disclosure issue (CWE-125) triggered via user interaction when a locally positioned attacker delivers a specially crafted Microsoft Office file for the victim to open; the underlying mechanism is an out-of-bounds read in Office.

If affected, business impact
Confidential documents leakedCustomer or employee data exposureRisk of account and business fraudIncident response and downtime costs

What to do now

  1. Check which Microsoft Office/Microsoft 365 version you run (Windows and/or Mac) and confirm whether you have any of these affected products installed: microsoft 365 apps, microsoft office, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, microsoft 365, office 2016, office 2019, office 2021, office 2024.
  2. Update Microsoft Office on each device to the fixed version for your product.
  3. If you can’t update right away, restrict opening files from untrusted sources (especially email attachments and downloaded documents) until updates are applied.
  4. Review device logs for unusual Office file-opening activity tied to unexpected documents, and remove any suspicious files/sources from user access.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:NA:N
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-63524 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows