Impact
The vulnerability stems from Microsoft Office's reliance on untrusted inputs in a security decision, which allows an unauthorized attacker to bypass a security feature locally. This weakness is classified as CWE‑807, reflecting improper validation of internal data inputs.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 are impacted. All installed versions of these products include the affected feature, with no specific sub‑release details provided.
Risk and Exploitability
With a CVSS base score of 7.8, the vulnerability is considered high risk. An EPSS score of 12% indicates a relatively high likelihood of exploitation. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector likely involves local execution by delivering an Office file from an untrusted source; network privileges are not required, and the exploit can be performed by users with local access.
OpenCVE Enrichment