CVE-2026-63524
Microsoft Office Information Disclosure Vulnerability
Description
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
In plain language
AI Act nowCVE-2026-63524 is a Microsoft Office bug that can expose confidential information if someone with local access gets you to open a specially made Office file; most small businesses should patch, but it’s not an automatic internet threat.
CVE-2026-63524 is a Microsoft Office information disclosure issue (CWE-125) triggered via user interaction when a locally positioned attacker delivers a specially crafted Microsoft Office file for the victim to open; the underlying mechanism is an out-of-bounds read in Office.
What to do now
- Check which Microsoft Office/Microsoft 365 version you run (Windows and/or Mac) and confirm whether you have any of these affected products installed: microsoft 365 apps, microsoft office, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, microsoft 365, office 2016, office 2019, office 2021, office 2024.
- Update Microsoft Office on each device to the fixed version for your product.
- If you can’t update right away, restrict opening files from untrusted sources (especially email attachments and downloaded documents) until updates are applied.
- Review device logs for unusual Office file-opening activity tied to unexpected documents, and remove any suspicious files/sources from user access.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63524 and every CVE in our database. Create a free account — no credit card required.
Create Free Account