CVE-2026-63519: Microsoft Office Graphics Component Remote Code Execution Vulnerability
A security vulnerability has been identified in the Microsoft Office Graphics Component that could allow an attacker to run malicious code remotely on a victim's system.

English Brief
A security vulnerability has been identified in the Microsoft Office Graphics Component that could allow an attacker to run malicious code remotely on a victim's system.
الموجز العربي
ثغرة CVE-2026-63519: تنفيذ التعليمات البرمجية عن بُعد في مكون رسومات Microsoft Office
تم تحديد ثغرة أمنية في مكون الرسومات ببرنامج Microsoft Office قد تسمح لمهاجم بتشغيل تعليمات برمجية ضارة عن بُعد على جهاز الضحية.
- 1Inventory every affected affected systems deployment and identify its owner.
- 2Apply the vendor security update or documented mitigation as soon as possible.
- 3Restrict external exposure and privileged access until remediation is verified.
English Advisory
// Intelligence Summary
CVE-2026-63519 describes a Remote Code Execution (RCE) vulnerability within the Microsoft Office Graphics Component. The flaw represents a significant risk as it allows unauthorized execution of code if a user opens a specially crafted file.
التقرير العربي
// ملخص استخباراتي
تصف الثغرة CVE-2026-63519 ثغرة تنفيذ تعليمات برمجية عن بُعد (RCE) داخل مكون رسومات Microsoft Office. تشكل هذه الثغرة خطراً كبيراً لأنها تسمح بتنفيذ تعليمات برمجية غير مصرح بها إذا قام المستخدم بفتح ملف معد خصيصاً لهذا الغرض.
// Technical Context
The vulnerability resides in how the Graphics Component handles object memory within Office applications. Insufficient validation of input structures can lead to memory corruption, which may be leveraged by an attacker to execute arbitrary code within the security context of the logged-in user.
// السياق الفني
تكمن الثغرة في كيفية تعامل مكون الرسومات مع ذاكرة الكائنات داخل تطبيقات Office. يمكن أن يؤدي التحقق غير الكافي من هياكل الإدخال إلى تلف في الذاكرة، وهو ما يمكن استغلاله من قبل المهاجم لتنفيذ تعليمات برمجية عشوائية ضمن سياق الأمان الخاص بالمستخدم المسجل دخوله.
// Exposure Notes
Users running affected versions of Microsoft Office are at risk if they interact with malicious files. The exploitability is limited to scenarios where a victim is convinced to open a crafted document.
// ملاحظات التعرض
المستخدمون الذين يقومون بتشغيل إصدارات متأثرة من Microsoft Office معرضون للخطر إذا تعاملوا مع ملفات ضارة. تقتصر قابلية الاستغلال على السيناريوهات التي يتم فيها إقناع الضحية بفتح مستند مفخخ.
// Defensive Priority
Organizations should prioritize the deployment of patches provided by Microsoft. Until patches are applied, users should exercise caution with documents received from untrusted sources.
// أولوية الدفاع
يجب على المؤسسات إعطاء الأولوية لتطبيق التصحيحات التي توفرها Microsoft. حتى يتم تطبيق التصحيحات، يجب على المستخدمين توخي الحذر عند التعامل مع المستندات التي يتم تلقيها من مصادر غير موثوقة.
Mitigation Checklist
- 1Inventory every affected affected systems deployment and identify its owner.
- 2Apply the vendor security update or documented mitigation as soon as possible.
- 3Restrict external exposure and privileged access until remediation is verified.
- 4Monitor authentication, process, file, and outbound-network telemetry for exploitation signals.
- 5Record validation evidence and retain compensating controls until remediation is closed.
قائمة إجراءات التخفيف
- 1حصر جميع عمليات نشر الأنظمة المتأثرة المتأثرة وتحديد مالكيها.
- 2تطبيق تحديث الأمان أو التخفيف الموثق من المورّد بأسرع وقت.
- 3تقييد الوصول الخارجي والصلاحيات العالية إلى أن يتم التحقق من المعالجة.
- 4مراقبة سجلات المصادقة والعمليات والملفات والاتصالات الخارجية بحثاً عن مؤشرات استغلال.
- 5توثيق أدلة التحقق والإبقاء على الضوابط التعويضية حتى إغلاق المعالجة.
- Source: Microsoft Security Response Center
# Update Microsoft Office via Microsoft Update or WSUS; # Ensure 'Protected View' is enabled for all Office documents; # Disable untrusted macros via GPO.