Impact
The reported flaw is a heap-based buffer overflow that permits an attacker to run arbitrary code inside the Office process, effectively allowing local code execution with the permissions of the user who opens a crafted document or attachment.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Office 2016 (x86), Office 2019, Office LTSC 2021 (Long Term Servicing Channel), and Office LTSC 2024 (Long Term Servicing Channel) on all supported architectures.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves delivering a malicious document to a user; therefore, any user who opens suspect content could be compromised. Prompt patching mitigates the risk.
OpenCVE Enrichment