Impact
The vulnerability occurs when Microsoft Office accesses an uninitialized resource, allowing an attacker with local unauthorized access to read data that should remain confidential. This flaw can expose sensitive documents or configuration information stored on the target machine and is classified under CWE‑908.
Affected Systems
Affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version details are not disclosed beyond these product families.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while the EPSS score of less than 1 percent indicates an exceptionally low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring the attacker to have unauthorized local access or the ability to execute code within an Office process, thus limiting the attack surface to users who have the software installed.
OpenCVE Enrichment