Impact
The vulnerability is an out‑of‑bounds read in Microsoft Word (CWE‑125). An attacker can exploit this flaw to read past memory boundaries and execute arbitrary code locally with the privileges of the user who opens a crafted document. This enables the attacker to read or modify critical data, alter files, and potentially gain elevated privileges within the local system, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All deployments of these product lines are vulnerable until a vendor‑supplied fix is installed, as no patched version is listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 places the flaw in the high severity category, while the EPSS score of <1% indicates a very low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would craft a malicious Word document and rely on a user opening it, making the attack vector a user‑initiated exposure. Defenses such as disabling automatic download of Office documents from email, restricting macro execution, and implementing content filtering can mitigate the risk.
OpenCVE Enrichment