CVE-2026-63518 – Microsoft Office Word Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a routine document open into code execution, putting sensitive data and system integrity at risk.”

CVE-2026-63518 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in Microsoft Office Word. An attacker can send a malicious Office file and convince a user to open it, triggering code execution on the local machine. No attacker privileges are required, but user interaction is necessary. Confidentiality, integrity, and availability can all be impacted.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
Successful exploitation can allow an unauthorized attacker to execute code locally. The vulnerability has low attack complexity and requires no attacker privileges, although the targeted user must open a malicious Office file. A successful attack can have a high impact on confidentiality, integrity, and availability.

EXPLOITS:
The vulnerability is not publicly disclosed and is not known to be exploited. Exploit code maturity is classified as Unproven, and exploitation is assessed as less likely. The source does not confirm the existence of public exploit code, a zero-day exploit, or proof-of-concept code.

TECHNICAL SUMMARY:
CVE-2026-63518 is a heap-based buffer overflow vulnerability in Microsoft Office Word. It can allow an unauthorized attacker to execute code locally after a user opens a specially crafted malicious Office file. Although the vulnerability title describes remote code execution because the attacker can be remote, the CVSS attack vector is Local. Exploitation has low complexity, requires no privileges, and requires user interaction. Successful exploitation can result in high confidentiality, integrity, and availability impact.

EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise on 32-bit and 64-bit systems, Office 2019, Office LTSC 2021 and 2024, Office 365 for Mac, Office LTSC for Mac 2021 and 2024, and Outlook 2016 32-bit and 64-bit editions. Exploitation requires the victim to open a malicious Office file.

BUSINESS IMPACT:
Successful exploitation could allow attacker-controlled code to run on an affected system, creating risks to sensitive information, system integrity, and service availability. In an organization, a malicious document could turn a common user action into a serious endpoint compromise.

WORKAROUND:
No workaround or mitigation is identified. An official fix is available, so affected Office installations should be updated.

URGENCY:
This vulnerability is rated Critical and can result in code execution with high confidentiality, integrity, and availability impact. While exploitation is assessed as less likely and no active exploitation is identified, organizations should prioritize deployment of the official fix because opening a malicious Office file can trigger the vulnerability.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.