Impact
An integer overflow or wraparound bug exists in Microsoft Office that permits an attacker with local access to read or disclose sensitive information. The flaw stems from improper handling of integer arithmetic, which can corrupt data boundaries and expose memory contents. As a result, a local user or program may obtain confidential data stored within Office files or the local system. The weakness is classified as CWE-190.
Affected Systems
All specified Microsoft Office products, including Office 2016, Office 2019, Office 2021, Office 2024, Office 365 for Mac, the Long-Term Servicing Channel releases for 2021 and 2024, and the Mac variants, as well as Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No particular version numbers are provided beyond the product families.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity risk for local attackers. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The primary attack vector is local, requiring an adversary to run malicious code or documents on the target system. Because the flaw permits information disclosure rather than arbitrary code execution, the impact is limited to confidentiality of data accessible from the local environment.
OpenCVE Enrichment