Impact
A type confusion flaw in Microsoft Office Word allows an unauthorized attacker to execute code locally when a vulnerable document is opened. The vulnerability arises from accessing a resource using an incompatible type, leading to a local code execution that can compromise the user's machine.
Affected Systems
The vulnerability affects Microsoft Word and related Office products including Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft Word 2016. Version details were not specified in the provided information.
Risk and Exploitability
With a CVSS score of 8.4, the flaw is considered high severity. The EPSS score is < 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation yet but still requiring vigilance. Based on the description, the likely attack vector involves opening a maliciously crafted Office document, granting the attacker local code execution on the victim’s machine. The impact is limited to the compromised system and does not inherently provide network or remote code execution without user interaction.
OpenCVE Enrichment