Impact
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Affected Systems
The flaw affects Microsoft Office LTSC 2024, specifically Outlook and Word. The affected product variants include the long‑term servicing channel for both x86 and x64 builds.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the near term. No KEV listing is present, suggesting no widespread exploitation has been reported. The vulnerability is a local code execution; the likely trigger is a specially crafted Office file that a user opens, either from a local source or via email attachment.
OpenCVE Enrichment