Impact
This vulnerability is a heap‑based buffer overflow (CWE‑122) in Microsoft Office Word. An attacker can embed malicious content in a Word document or SharePoint file such that when the victim opens it, the overflow occurs, allowing arbitrary code to execute with the privileges of the user who launched Word.
Affected Systems
Affected products include Microsoft Word 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, the Office LTSC 2021 and LTSC 2024 editions, and all Microsoft SharePoint Server 2016, 2019 and Subscription Edition deployments. Version details are not supplied in the advisory, so administrators should verify that their installations are at least on the latest cumulative update for the respective product line.
Risk and Exploitability
The CVSS score of 7.8 represents high severity, with a local privilege requirement and user interaction. The EPSS of less than 1% suggests a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious file could be delivered via SharePoint, but the advisory does not explicitly state SharePoint as an attack vector; the attack vector requires a user to open a malicious document locally or via SharePoint; it cannot be triggered remotely over the network.
OpenCVE Enrichment