Impact
Buffer over‑read in Microsoft Office allows an unauthorized attacker to disclose information locally. The flaw is a buffer over‑read (CWE‑126) that can lead to reading sensitive data in memory.
Affected Systems
The flaw affects multiple Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, the LTSC 2021 and LTSC 2024 releases, and LTSC for Mac 2021 and LTSC for Mac 2024 editions, and the Office for Android application. The CVE entry does not list specific sub‑versions or build numbers, so all current releases of the mentioned products are potentially impacted.
Risk and Exploitability
The CVSS score of 4.7 indicates low severity, and the EPSS score of < 1% (≈ 0.00357) indicates a very low but nonzero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local because the description states that an unauthorized local attacker can exploit the flaw; it is also inferred that a user or process with privileges sufficient to load Office documents may trigger the out‑of‑bounds read. Attackers can thus potentially read and disclose data that resides in Office’s memory space.
OpenCVE Enrichment