Impact
Based on the updated description, a heap‑based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally by overflowing heap memory when processing Office documents. The overflow can overwrite control data, enabling the attacker to run arbitrary code with the privileges of the user who opens the malicious file, which results in local code execution.
Affected Systems
The flaw affects Microsoft Office LTSC 2024, specifically Outlook and Word. The affected product variants include the long‑term servicing channel for both x86 and x64 builds.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the near term. No KEV listing is present, suggesting no widespread exploitation has been reported. The vulnerability is a local code execution; the likely trigger is a specially crafted Office file that a user opens, either from a local source or via email attachment.
OpenCVE Enrichment