Impact
The flaw is a heap‑based buffer overflow in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code when a vulnerable Office file is opened or the application is interacted with. The vulnerability is a classic CWE‑122 condition, where the application fails to enforce correct bounds checking on user supplied data. The impact is local code execution, granting the attacker control over the affected machine. Based on the description, it is inferred that the attack does not require network connectivity; it can be triggered by opening a crafted Office document on the local system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version details are not provided by the advisory, so administrators should apply the latest update that addresses CVE‑2026‑63533 for the specific Office version in use.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is classified as high severity. The EPSS score is less than 1 %, indicating a very low probability of exploitation in the wild at the time of this analysis. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploitation yet. Because the flaw requires a user to open a malicious Office document, the attack vector is local; an attacker can succeed after delivering a crafted file via email or a network share. The absence of a remote trigger reduces the exponential spread potential but still poses a significant threat to any machine that processes Office files from untrusted sources.
OpenCVE Enrichment