Impact
Out‑of‑bounds read bug exists in Microsoft Office products that allows an unauthorized local attacker to read memory beyond the intended buffer, potentially leaking sensitive data from the application or the host system. The vulnerability is triggered by normal Office operation and can expose confidential information without any authentication beyond local access.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021 and Office LTSC for Mac 2024. No specific patch version data is supplied, so any installations of these product lines are considered vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates significant risk, yet the EPSS is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to a user running the affected Office product lines; an attacker could use a crafted Office file or other input to trigger the vulnerability leading to disclosure of data that resides in the process address space.
OpenCVE Enrichment