Impact
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. The description does not detail the exact trigger, but it is inferred that a malicious Office document or object may be required to exploit the flaw. The code would run with the privileges of the user who opens the document.
Affected Systems
All Office products listed as affected by the advisory—Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android—are vulnerable. The these products should be assumed vulnerable until an update that addresses the issue is installed.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of less than 1% shows a very low likelihood of exploitation currently, and the vulnerability is not listed in the CISA KE description, it is inferred that the likely attack vector is a local user interacting with a malicious Office object or document; no remote exploitation pathway is described. The exploit would execute code with the privileges of the user who opens the object.
OpenCVE Enrichment