Impact
A use‑after‑free flaw in Microsoft Office Word permits an attacker to execute code on the affected system without explicit user privilege elevation. The vulnerability can lead to full compromise of confidentiality, integrity, and availability by allowing arbitrary code to run with the current user’s permissions. The weakness is classified as CWE‑416: Use After Free.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024 (both Windows and Mac), Microsoft Word 2016, and SharePoint Server releases 2016, 2019, and Subscription Edition are all affected. All releases encompassed by the product families listed are presumed vulnerable due to the lack of version‑specific exclusions.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires an attacker to provide a malicious Office document or otherwise trigger Word processing locally, implying an interactive or user‑initiated attack vector. If the user opens a crafted file, local code execution can occur, potentially escalating to full system compromise.
OpenCVE Enrichment