Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office components that enables an unauthorized local attacker to access sensitive data. This weakness allows reading memory beyond intended bounds, potentially exposing user information or internal configuration details. The flaw is classified as CWE‑125 and can compromise confidentiality.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Version information is not explicitly specified in the advisory, so all current releases of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, while the EPSS score of less than 1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, which further suggests limited known exploitation. The attack vector is likely local, requiring the attacker to be able to execute Office‑related code or craft a malicious document that triggers the out‑of‑bounds read. Because the flaw only permits data leakage rather than arbitrary code execution, the overall threat remains moderate unless the accessed information is highly sensitive.
OpenCVE Enrichment