Description
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read flaw in Microsoft Office Word allows an attacker who can locally execute or instruct the application to process a crafted document to read memory contents that should be protected. This abuse of inadequate boundary checks is a CWE‑125 vulnerability and can reveal whatever data resides in the accessed memory at run time, potentially including sensitive or confidential information. The impact is limited to disclosure of information; it does not modify data or grant control over the system.

Affected Systems

The flaw affects all current releases of Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016, as listed by the CNA. Without specific version ranges the safest assumption is that every shipped version remains vulnerable until the Microsoft security update is applied.

Risk and Exploitability

With a CVSS base score of 5.5 the issue is assessed as moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating low public exploitation risk. The likely attack vector is local; an attacker needs either local access or to convince a user to open a malicious document that triggers the out‑of‑bounds read when Word processes it. Because the flaw only allows reads, non‑privileged local execution is sufficient to obtain the disclosed information, but no privileged escalation or remote code execution is possible.

Generated by OpenCVE AI on August 12, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Office security update that resolves the out‑of‑bounds read issue, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521.
  • Configure Office to open documents from external or untrusted sources in Protected View and disable macros in that context to reduce the risk of file‑based exploitation.
  • Keep all Office applications and the underlying operating system up to date with the latest cumulative or security updates so safeguards against other vulnerabilities are also applied.

Generated by OpenCVE AI on August 12, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft word
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft word

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Title Microsoft Office Word Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft word 2016
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:34.101Z

Reserved: 2026-07-16T22:05:22.740Z

Link: CVE-2026-63521

cve-icon Vulnrichment

Updated: 2026-08-12T15:29:06.949Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:48.867

Modified: 2026-08-14T17:33:26.280

Link: CVE-2026-63521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T15:30:03Z

Weaknesses