Impact
A heap‑based buffer overflow in Microsoft Office permits an unauthorized attacker to execute code locally with the privileges of the user who opens the vulnerable content. The flaw, identified as CWE‑122, enables arbitrary code execution, potentially compromising confidentiality, integrity and availability of the affected system.
Affected Systems
Affected systems include Microsoft 365 Apps for Enterprise; Microsoft Office 2016, 2019, 2021, 2024; Office 365 for Mac; Office LTSC 2021 and 2024; Office LTSC for Mac 2021 and 2024; and SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. All listed releases are potentially impacted.
Risk and Exploitability
The CVSS base score of 7.8 indicates high risk severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack is likely to involve a local user opening a crafted Office document, after which arbitrary code can run. Despite the low exploitation probability, the potential impact warrants prompt remediation.
OpenCVE Enrichment