Impact
The vulnerability is a stack‑based buffer overflow (CWE‑121) within Microsoft Office Word that allows an attacker to force execution of arbitrary code when an infected document is opened. The flaw provides local code execution only; it does not grant elevation beyond the privileges of the user who opens the file, nor does it enable remote access.
Affected Systems
Affected products span Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, the Long‑Term Servicing Channel releases of Office 2021 and 2024, Office for Mac editions of 2021 and 2024, Word 2016, and several SharePoint Server deployments. No specific version ranges are supplied beyond the product families listed.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present; the vulnerability is not cataloged in CISA’s KEV list. Based on the description, it is inferred that the attack vector is a malicious Office document delivered to a local user, which when opened triggers the stack overflow to execute attacker code on that machine.
OpenCVE Enrichment