Impact
Based on the description, it is inferred that the likely attack vector is a malicious Word document that a user opens. Heap‑based buffer overflow in Microsoft Office Word permits an attacker to execute arbitrary code with the privileges of the user who opens a crafted document. The flaw can be triggered without user interaction beyond opening a malicious file, enabling a remote adversary to compromise local systems. This weakness is a classic buffer overflow (CWE‑122) and represents a high‑severity vulnerability.
Affected Systems
Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition, and Microsoft Word 2016 are all affected. No specific sub‑version range was supplied, so all current iterations of these products remain vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is a malicious document that a user opens. The CVSS score of 7.8 indicates high severity, but the EPSS score is under 1 %, signifying that real‑world exploitation is rare at present. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is local, execution would occur when an authenticated or local attacker accesses Word with the malicious content, and no network exposure is implied.
OpenCVE Enrichment