Impact
Improper access control in Microsoft Office Word for Android allows an authorized attacker to perform spoofing locally. This weakness, classified as CWE-284, permits a malicious user who has legitimate access to impersonate or misrepresent themselves within the application. The primary impact is the ability to forge identity or content without permission; however, it does not grant remote code execution or full system compromise.
Affected Systems
The vulnerability affects Microsoft Word for Android. No specific version range is listed, so all installations of Word for Android should be treated as potentially vulnerable until an official patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium-high severity. No EPSS score is available, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is local; an attacker must already have authorized access to the device or the app. Because the flaw is an access control failure, it is straightforward for a local attacker to exploit it once the conditions are met.
OpenCVE Enrichment