Impact
The vulnerability is an out‑of‑bounds read that allows an attacker to read memory containing sensitive data, resulting in local information disclosure. This flaw is identified as CWE‑125. The impact is limited to confidentiality loss for data that may be stored in Office documents or user session memory; there is no known effect on integrity or availability.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, 2019, 2021, 2024, Office 365 for Mac, Office LTSC 2021 and 2024, and the corresponding Mac versions. SharePoint Server products such as SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are also listed as affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited current exploit landscape. Because the exploit requires local access to an Office installation, the likely vector is a local user or malicious code executing on the infected host. The attacker can read data from memory buffers that are improperly bounded, leading to the disclosure of sensitive information.
OpenCVE Enrichment