Impact
The issue is an out‑of‑bounds read (CWE‑125) that lets an attacker with local access read memory that should be private, exposing any data stored on the affected system. The vulnerability is limited to local exploitation; based on the description, it is inferred that an attacker must be able to run or otherwise trigger Office to execute the vulnerable code path.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2021 LTSC, Microsoft Office 2024 LTSC, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all impacted. Specific patch versions are provided by Microsoft in the security update, but the list above represents all releases that the vendor has identified as affected.
Risk and Exploitability
With a CVSS of 5.5, the risk is moderate, yet the EPSS of <1% and absence of a KEV listing suggest exploitation is currently unlikely. Because the flaw is local, organizations should treat it as a medium risk until a patch is applied.
OpenCVE Enrichment