CVE-2026-63513: Microsoft Office Graphics Component Remote Code Execution Vulnerability
A security vulnerability has been identified in the Microsoft Office Graphics Component that could allow an attacker to execute malicious code on your computer if you open a specially crafted file.

English Brief
A security vulnerability has been identified in the Microsoft Office Graphics Component that could allow an attacker to execute malicious code on your computer if you open a specially crafted file.
الموجز العربي
CVE-2026-63513: ثغرة تنفيذ تعليمات برمجية عن بعد في مكون رسومات Microsoft Office
تم تحديد ثغرة أمنية في مكون رسومات Microsoft Office قد تسمح للمهاجم بتنفيذ تعليمات برمجية ضارة على جهاز الكمبيوتر الخاص بك إذا قمت بفتح ملف معد خصيصاً.
- 1Open Microsoft Update or Windows Update settings.
- 2Check for the latest security updates for Microsoft Office.
- 3Install all available patches and restart the system.
English Advisory
// Intelligence Summary
CVE-2026-63513 is a remote code execution vulnerability residing in the Microsoft Office Graphics Component. The flaw allows an unauthenticated attacker to execute arbitrary code within the context of the current user when a victim opens a malicious document.
التقرير العربي
// ملخص استخباراتي
تعد CVE-2026-63513 ثغرة تنفيذ تعليمات برمجية عن بعد موجودة في مكون رسومات Microsoft Office. تسمح هذه الثغرة للمهاجم غير المصادق عليه بتنفيذ تعليمات برمجية تعسفية في سياق المستخدم الحالي عند قيام الضحية بفتح مستند ضار.
// Technical Context
The vulnerability exists due to improper handling of graphic objects within the Microsoft Office suite. When the component parses a malformed file, a memory corruption issue occurs, which can be leveraged to achieve code execution.
// السياق الفني
توجد الثغرة بسبب المعالجة غير الصحيحة للكائنات الرسومية داخل حزمة Microsoft Office. عند قيام المكون بتحليل ملف غير صالح، تحدث مشكلة تلف في الذاكرة، والتي يمكن استغلالها لتنفيذ التعليمات البرمجية.
// Exposure Notes
Users running affected versions of Microsoft Office are at risk if they open untrusted files from external sources. The complexity of the attack is currently unknown, but typically requires the user to interact with a specially crafted file.
// ملاحظات التعرض
المستخدمون الذين يشغلون إصدارات متأثرة من Microsoft Office معرضون للخطر إذا قاموا بفتح ملفات غير موثوقة من مصادر خارجية. تعقيد الهجوم غير معروف حالياً، ولكنه يتطلب عادةً تفاعل المستخدم مع ملف معد خصيصاً.
// Defensive Priority
Organizations should prioritize patching affected Office installations as soon as official updates from Microsoft are deployed. Organizations should also enforce file-type restrictions and use endpoint security solutions to monitor for anomalous behavior in Office processes.
// أولوية الدفاع
يجب على المؤسسات إعطاء الأولوية لتطبيق التصحيحات على إصدارات Office المتأثرة بمجرد توفر التحديثات الرسمية من Microsoft. يجب على المؤسسات أيضاً فرض قيود على أنواع الملفات واستخدام حلول أمن النقاط النهائية لمراقبة أي سلوك غير طبيعي في عمليات Office.
Mitigation Checklist
- 1Open Microsoft Update or Windows Update settings.
- 2Check for the latest security updates for Microsoft Office.
- 3Install all available patches and restart the system.
- 4Use Group Policy to disable macros or restrict loading of untrusted external content in Office files.
قائمة إجراءات التخفيف
- 1افتح إعدادات Microsoft Update أو Windows Update.
- 2تحقق من وجود آخر التحديثات الأمنية لـ Microsoft Office.
- 3قم بتثبيت جميع التصحيحات المتاحة وأعد تشغيل النظام.
- 4استخدم نهج المجموعة (Group Policy) لتعطيل الماكرو أو تقييد تحميل المحتوى الخارجي غير الموثوق به في ملفات Office.
- Source: Microsoft Security Response Center
# Checklist for remediating CVE-2026-63513:
# 1. Open Microsoft Update or Windows Update settings.
# 2. Check for the latest security updates for Microsoft Office.
# 3. Install all available patches and restart the system.
# 4. Use Group Policy to disable macros or restrict loading of untrusted external content in Office files.