Impact
An integer overflow or wraparound flaw (CWE‑190) in Microsoft Office Word is also a buffer overflow (CWE‑122). The bug can be triggered by processing a specially crafted document, allowing an attacker with access to the file to execute arbitrary code locally using the privileges of the current user. This flaw exposes confidentiality, integrity, and availability risks and can serve as a foothold for lateral movement if privilege escalation follows.
Affected Systems
This vulnerability affects several Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 2016, Office for Mac 2021, Office for Mac 2024, Word 2016, and SharePoint Server versions 2016, 2019, and Subscription Edition. Exact affected product versions are not enumerated in the data; however every recent release of the listed products is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw, and the EPSS score is <1%, indicating a low probability of exploitation. The vulnerability is not in CISA KEV. Based on the description, the most plausible attack vector is local file processing – an attacker who can supply a malicious document to a user or a system service will trigger the overflow. Thus an unauthenticated or authenticated local user can exploit the flaw. No elevated trust or network interaction is necessary. While the flaw is not yet seen in widespread exploitation, its high severity and local nature still warrant prompt remediation.
OpenCVE Enrichment