CVE-2026-63525 – Microsoft Office Word Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a simple document open into code execution, putting sensitive data and systems at risk.”

CVE-2026-63525 is a critical remote code execution vulnerability caused by a numeric truncation error in Microsoft Office Word. An attacker can send a specially crafted Office file and convince a user to open it, resulting in code execution on the local machine. Exploitation requires no privileges but does require user interaction. The vulnerability is not publicly disclosed and is not currently exploited.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
Successful exploitation can allow an unauthorized attacker to execute code locally, with potentially high impact to confidentiality, integrity, and availability. The attack complexity is low and no privileges are required, although a targeted user must open a malicious Office file.

EXPLOITS:
The vulnerability is assessed as exploitation less likely. It is not publicly disclosed and is not known to be exploited. Exploit code maturity is listed as unproven, so confirmed public exploit or proof-of-concept code cannot be established from the source information.

TECHNICAL SUMMARY:
CVE-2026-63525 results from a numeric truncation error, identified as CWE-197, in Microsoft Office Word. The vulnerability can allow an unauthorized attacker to execute code locally. Although classified as remote code execution because the attacker may operate remotely, exploitation itself occurs on the victim's local machine. An attacker must deliver a malicious Office file and persuade the user to open it. The Preview Pane is not an attack vector. The vulnerability has low attack complexity, requires no privileges, requires user interaction, and can have high confidentiality, integrity, and availability impact.

EXPLOITABILITY:
Affected products include 32-bit and 64-bit Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft Word 2016. Exploitation requires the victim to open a malicious Office file.

BUSINESS IMPACT:
Successful exploitation could expose sensitive information, allow unauthorized modification of data, and disrupt system availability. Because malicious code can execute without the attacker already having privileges, a successful document-based attack could create significant security and operational impact.

WORKAROUND:
No workaround or mitigation is identified. An official fix is available, making patch deployment the documented remediation path.

URGENCY:
This vulnerability is rated Critical and can lead to code execution with high confidentiality, integrity, and availability impact. Although it is not known to be exploited and exploitation is assessed as less likely, organizations should prioritize the official fix because exploitation requires no existing privileges and has low attack complexity.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-197
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.