CVE-2026-63532

Summary

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office 201616.0.0 < 16.0.5565.1001affected
MicrosoftMicrosoft Office 201919.0.0 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office 365 for Mac1.0.0 < 16.112.26081010affected
MicrosoftMicrosoft Office LTSC 202116.0.1 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC 202416.0.0 < https://aka.ms/OfficeSecurityReleasesaffected
MicrosoftMicrosoft Office LTSC for Mac 202116.0.1 < 16.112.26081010affected
MicrosoftMicrosoft Office LTSC for Mac 202416.0.0 < 16.112.26081010affected

Weaknesses

  • CWE-190: CWE-190: Integer Overflow or Wraparound
  • CWE-122: CWE-122: Heap-based Buffer Overflow

References