CVE-2026-63513 – Microsoft Office Graphics Component Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a simple document open or Preview Pane action into an opportunity to run attacker-controlled code.”

CVE-2026-63513 is a heap-based buffer overflow in the Microsoft Office Graphics Component that can allow an unauthorized attacker to execute code locally. An attacker must deliver a malicious Office file and convince the user to open it, while the Preview Pane can also act as an attack vector. Successful exploitation can result in high impact to confidentiality, integrity, and availability.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
The vulnerability creates a remote code execution risk through malicious Office content. Although the CVSS attack vector is Local, the attacker can be remote and deliver a crafted Office file that triggers exploitation when processed on the local system. Attack complexity is Low, no privileges are required, and user interaction is required.

EXPLOITS:
The vulnerability is not publicly disclosed and is not known to be exploited. Its exploitability assessment is Exploitation Less Likely, and exploit code maturity is Unproven. The source does not confirm the existence of public exploit code, a zero-day exploit, or proof-of-concept code.

TECHNICAL SUMMARY:
CVE-2026-63513 is caused by a heap-based buffer overflow in the Microsoft Office Graphics Component. A malicious Office file can trigger the vulnerability when processed locally. The attacker must send the crafted file to a user and convince them to open it; the Preview Pane is also identified as an attack vector. Successful exploitation can allow arbitrary code execution, with high potential impact to confidentiality, integrity, and availability. The vulnerability requires no attacker privileges but does require user interaction.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. Exploitation requires malicious Office content to be processed locally, with user interaction required.

BUSINESS IMPACT:
Successful exploitation could allow attacker-controlled code to run on an affected system, potentially compromising sensitive information, altering data, and disrupting system availability. Malicious Office documents also present a practical delivery mechanism for attacks, making exposure to untrusted files an important organizational risk.

WORKAROUND:
No workaround or mitigation is listed. An official fix is identified as the remediation, so affected Office installations should be patched through the applicable update mechanism.

URGENCY:
This vulnerability is rated Critical and can lead to code execution with high confidentiality, integrity, and availability impact. Although exploitation is assessed as less likely and no active exploitation is identified, affected Microsoft Office products should be prioritized for deployment of the official fix.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.