Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office that allows an unauthorized attacker to execute code locally. This memory corruption flaw can lead to arbitrary code execution on the affected machine, granting the attacker control over the Office process with the privileges of the logged‑in user.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. All indicated versions are impacted; no specific patch level is provided in the CIA source, so any installation of these products may be vulnerable.
Risk and Exploitability
The CVSS score of 8.4 reflects high severity, indicating the potential for significant compromise if the flaw is used. The EPSS score of 0.057% indicates a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog, so there is currently no evidence of widespread exploitation. The likely attack vector is local, requiring the attacker to run malicious code or documents on the target machine. No remote attack path is described in the available data.
OpenCVE Enrichment