CVE-2026-63524: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63524?
CVE-2026-63524 has a medium severity rating of 5.5.
How do I fix CVE-2026-63524?
To fix CVE-2026-63524, update Microsoft Office to the latest version provided by Microsoft.
What type of vulnerability is CVE-2026-63524?
CVE-2026-63524 is classified as an information disclosure vulnerability.
Which software products are affected by CVE-2026-63524?
The vulnerable software includes Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office 2019, Microsoft Office 2021, and Microsoft Office 2024.
What can an attacker do with CVE-2026-63524?
An unauthorized attacker can use CVE-2026-63524 to disclose sensitive information locally through an out-of-bounds read.