Impact
An out‑of‑bounds read in Microsoft Office Word can be triggered by a local attacker with access to the user’s machine. The flaw allows reading of data that should be protected, potentially exposing confidential documents or other sensitive information in memory or on disk. The weakness is a classic buffer overread (CWE‑125) and does not provide code execution or denial of service, only unauthorized disclosure of data.
Affected Systems
The vulnerability impacts Microsoft Office products across several Windows and macOS versions, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office LTSC 2021, Office LTSC 2024, Office 365 for Mac, Office for Mac 2021, Office for Mac 2024, and Microsoft Word 2016. SharePoint Server affected editions include Enterprise Server 2016, Server 2019 and Server Subscription Edition.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity for a local information‑disclosure vulnerability. The EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. Attackers need local or privileged access to the target machine, so remote exploitation is not possible. The lack of exploitation evidence and the requirement for local access reduce overall risk.
OpenCVE Enrichment