Impact
The vulnerability is a heap-based buffer overflow in certain Microsoft Office applications. An attacker can execute arbitrary code locally. Such code execution would give the attacker full control of the compromised system, allowing further lateral movement or persistence.
Affected Systems
The flaw affects a range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021 and Office LTSC 2024. No specific version numbers were listed, so all releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is opening a specially crafted Office document, after a user is convinced to do so through social engineering or phishing, which can trigger the heap-based buffer overflow and grant the attacker local code execution with the victim's privileges. While exploitation is local, it can lead to full system compromise, enabling persistence or lateral movement.
OpenCVE Enrichment