Impact
A heap‑based buffer overflow in Microsoft Office allows an unauthorized attacker to execute arbitrary code within the context of the user’s session. The vulnerability can be triggered by opening a specially crafted document file, resulting in loss of confidentiality, integrity, or availability for the affected user and potentially the entire system.
Affected Systems
Affecting Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android with no specific versions listed.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability; no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Likely attack vector is local, requiring the attacker to supply a malicious file that a user opens. While user interaction is needed, the impact is significant due to the potential for arbitrary code execution.
OpenCVE Enrichment