Impact
Microsoft Office Word contains an improper input validation flaw that allows an unauthorized local user to disclose sensitive information. This vulnerability is mapped to CWE‑20 (Improper Input Validation) and CWE‑1287 (Information Disclosure).
Affected Systems
The flaw affects a broad range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, and Word 2016. SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are also affected. Version detail is not specified in the CVE.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability is considered moderate. The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is local only; an attacker must already have local access to a machine and exploit the flaw by submitting a crafted input that triggers the improper validation. As it is not listed in the CISA KEV catalog, there are no known widespread exploits, but the limited exploitability does not eliminate the need for vigilance.
OpenCVE Enrichment