CVE-2026-63532 – Microsoft Office Remote Code Execution Vulnerability

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious Office file can turn a routine document interaction into code execution with high impact to confidentiality, integrity, and availability.”

CVE-2026-63532 is a Critical Microsoft Office remote code execution vulnerability caused by an integer overflow or wraparound and a heap-based buffer overflow. An unauthorized attacker can exploit the vulnerability by convincing a user to open a malicious Office file. The Preview Pane is also an attack vector. Successful exploitation can execute code locally and result in high impact to confidentiality, integrity, and availability.

CVSS Score: 7.8.

SEVERITY: Critical.

THREAT:
An attacker can create a malicious Office file designed to trigger the vulnerability. Attack complexity is low and no privileges are required, although user interaction is required. The Preview Pane can also expose users to the attack vector.

EXPLOITS:
The vulnerability is not publicly disclosed and is not reported as exploited. Exploit code maturity is Unproven, and exploitation is assessed as Less Likely. No confirmed public exploit, zero-day exploitation, or proof-of-concept exploit code is identified.

TECHNICAL SUMMARY:
The vulnerability involves an integer overflow or wraparound and a heap-based buffer overflow in Microsoft Office. A specially crafted Office file can trigger the flaw and allow an unauthorized attacker to execute code locally. Although the vulnerability is categorized as remote code execution because the attacker may be remote, the actual code execution occurs on the local machine. Exploitation requires no privileges, has low attack complexity, and requires user interaction. Successful exploitation can have high confidentiality, integrity, and availability impact.

EXPLOITABILITY:
Affected products include Microsoft 365 Apps for Enterprise 32-bit and 64-bit, Microsoft Office 2016 and 2019 32-bit and 64-bit editions, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and 2024 32-bit and 64-bit editions, and Microsoft Office LTSC for Mac 2021 and 2024. An attacker can attempt exploitation using a malicious Office file that a user opens; the Preview Pane is also an attack vector.

BUSINESS IMPACT:
Successful exploitation could allow unauthorized code execution on an affected endpoint, creating high risks to the confidentiality, integrity, and availability of business information and systems. A weaponized Office document could therefore turn common document handling into a route for significant endpoint compromise.

WORKAROUND:
No workaround or mitigation is identified. An official fix is available, making patch deployment the documented remediation path.

URGENCY:
This vulnerability is rated Critical and can lead to remote code execution with high confidentiality, integrity, and availability impact. Organizations should prioritize deployment of the official fix across affected Microsoft Office installations, particularly because exploitation requires no privileges and the Preview Pane is an attack vector.

Key Details

Affected Product
Microsoft 365 Apps
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.