Impact
A use‑after‑free flaw in Microsoft Office Word permits an attacker to execute code with the privileges of the user who opens a corrupted document. The vulnerability allows arbitrary code execution locally, potentially compromising the confidentiality, integrity, and availability of the host system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft Word 2016.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, yet the EPSS score of <1% indicates a low probability of current exploitation. The vulnerability is not listed in CISA KEV. Based on the description and common exploitation patterns for use‑after‑free flaws in Office documents, it is inferred that an attacker would need to persuade a user to open a specially crafted Office file, which would trigger the corruption and grant code execution. Because user interaction is required, the risk remains moderate to high until a vendor patch is applied.
OpenCVE Enrichment