Impact
This vulnerability is a heap‑based buffer overflow (CWE‑122, CWE‑787) in Microsoft Office Word. An attacker can embed malicious content in a Word document or SharePoint file such that when the victim opens it, the overflow occurs, allowing arbitrary code to execute with the privileges of the user who launched Word.
Affected Systems
Affected products include Microsoft Word 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, the Office LTSC 2021 and LTSC 2024 editions, and all Microsoft SharePoint Server 2016, 2019 and Subscription Edition deployments. Version details are not supplied in the advisory, so administrators should verify that their installations are at least on the latest cumulative update for the respective product line.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity for this vulnerability. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious Word document could be delivered via SharePoint or other file distribution methods, but the advisory does not explicitly state SharePoint as an attack vector. The attack requires a victim to open the malicious document locally or through SharePoint; it cannot be triggered remotely over the network.
OpenCVE Enrichment