Impact
An out-of-bounds read in Microsoft Office Word can allow an unauthorized attacker to execute code locally. The flaw occurs when processing a crafted Word document, enabling arbitrary code execution with the privileges of the user’s document viewer.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All current releases of these products are potentially vulnerable until Microsoft releases a fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of <1% suggests a low but non-zero probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers are likely to deliver a malicious Word document to a user; once opened the file, code runs with the user’s rights, which could then be leveraged for privilege escalation or further compromise.
OpenCVE Enrichment