Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) that allows an attacker to execute arbitrary code within the Office process. The impact is local code execution; no remote exploitation or privilege escalation beyond the Office context is described in the available data. Specific vendor‑affected version details are not provided in the public advisory.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are affected when running the current distribution without the security update. No specific version information is available in the public advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for a local exploit, while the EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have access that allows execution of code within the Office process.
OpenCVE Enrichment