Impact
A buffer overread allows an attacker with local execution privileges to read memory that they should not be able to, potentially exposing confidential data such as documents, credentials or other sensitive information. The weakness is identified as CWE‑125 and, based on the description, the read can be triggered by a user interacting with office content, for example a malicious document or macro. The impact is that confidentiality may be compromised, but there is no evidence of integrity or availability loss.
Affected Systems
Affected are multiple Microsoft Office distributions: Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 2021, Office 2024, Office for Mac 2021, Office for Mac 2024, as well as SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. Specific patch release numbers are not listed in the provided reference, so all versions in the vendor/product list are considered vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests the vulnerability is very unlikely to be exploited in the wild at this time. The vulnerability is not listed in the CISA KEV catalogue, further indicating a low exploitation probability. Attackers would need local access to a system running a vulnerable Office version and the ability to supply malicious content, such as a crafted document or macro, to trigger the out‑of‑bounds read. No remote or network‑based attack path is described.
OpenCVE Enrichment