Impact
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Based on the description, it is inferred that the attack vector is local. The potential impact is local code execution, which can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version details are not disclosed in the available CNA data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of <1% points to a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The use‑after‑free in Word can enable local code execution if an attacker supplies a crafted document; however, the specific exploitation scenario is not detailed in the available data.
OpenCVE Enrichment