CVE-2026-63529: Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002897
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63529?
CVE-2026-63529 has a medium severity rating of 5.5.
How does CVE-2026-63529 affect Microsoft Office?
CVE-2026-63529 allows an unauthorized attacker to disclose sensitive information due to an out-of-bounds read in Microsoft Office.
Which Microsoft Office versions are impacted by CVE-2026-63529?
CVE-2026-63529 affects Microsoft 365 Apps for Enterprise, Office 2016, Office 2019 (both 32-bit and 64-bit), and Office LTSC versions 2021 and 2024.
What can be done to mitigate CVE-2026-63529?
To mitigate CVE-2026-63529, it is important to apply security updates and patches released by Microsoft.
Is user interaction needed for CVE-2026-63529 to be exploited?
Yes, CVE-2026-63529 requires user interaction to exploit the vulnerability.