Impact
The vulnerability is a heap‑based buffer overflow (CWE‑122) in Microsoft Office that allows an unauthorized attacker to execute arbitrary code locally on a compromised workstation. The flaw could enable an attacker to run malicious payloads that compromise the confidentiality, integrity, or availability of the affected system, potentially elevating privileges or allowing further exploitation of other software on the machine.
Affected Systems
Affected are Microsoft Office products across several releases, including Office 2016, Office 2019, Office 2021, Office 2024, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and SharePoint Server editions (2016, 2019, and Subscription).
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is rated high severity. EPSS data is not available, and it is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to place a malicious Office document in a location accessed by the victim; the user then must open or otherwise interact with the file for the heap overflow to be triggered.
OpenCVE Enrichment