Impact
A heap‑based buffer overflow in Microsoft Office permits an attacker who obtains an Office document to run arbitrary code on the affected machine. The flaw is a classic out‑of‑bounds write (CWE‑122) that leads to local code execution and would compromise confidentiality, integrity, and availability once triggered.
Affected Systems
Affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No explicit version ranges are provided, so any installed instance of these products is considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, indicating that successful exploitation would grant the attacker extensive local privileges. The EPSS score is reported as less than 1%, suggesting that observed exploitation in the wild is uncommon at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is delivery of a specially crafted Office document via email, web download, or other means that result in the user opening the file. If exploited, the attacker could execute arbitrary code with the same privileges as the user, potentially compromising the entire system.
OpenCVE Enrichment