Impact
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. This vulnerability is classified as CWE-121 (Stack-based Buffer Overrun) and CWE-191 (Integer Signed/Unsigned Conversion Error). The attack occurs when a malicious Office document or object is processed; the underflow can be triggered during local handling of the file, allowing arbitrary code execution with the privileges of the user who opens it.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android are affected and vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious Office object or document processed locally; it does not support remote exploitation and is limited to the privileges of the user who opens the file.
OpenCVE Enrichment