Impact
A heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally on a victim machine. The flaw is classified as CWE-122. Based on the description, it is inferred that the overflow is triggered when Office processes a maliciously crafted document, and upon exploitation the attacker gains the privileges of the logged‑in user, enabling further malicious activities such as malware installation or data theft.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are all vulnerable. No specific version constraints are listed; all current builds of these products may contain the flaw.
Risk and Exploitability
The CVSS score of 7.8 categorizes the flaw as high severity, and the EPSS score of < 1% indicates a low probability of widespread exploitation at this time. Based on the description, it is inferred that the likely attack vector involves opening a malicious Office document locally, which triggers the overflow. Because it is not listed in the CISA KEV catalog, no active exploitation campaigns are known. However, once exploited, the flaw delivers local code execution, offering significant compromise potential for the affected system.
OpenCVE Enrichment