Impact
This vulnerability stems from an integer overflow or wraparound condition in Microsoft Office. Based on the description, it is inferred that the overflow can cause local information disclosure to an unauthorized attacker. The flaw is identified as CWE-190, which relates to improper handling of integer calculations.
Affected Systems
The CVE affects multiple Office packages, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, Office 365 for Mac, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. No specific version ranges are stated, so all current installations of these products should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% reflects a low likelihood of exploitation in the current landscape. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a local attacker could exploit the flaw to access information available on the host. Overall, the risk remains moderate to low, and applying a patch mitigates the threat.
OpenCVE Enrichment