Impact
Based on the description, it is inferred that a double free flaw in Microsoft Office Word can be triggered by a specially crafted document, allowing an unauthorized attacker to execute code locally when the user opens the document, giving the attacker code execution privileges in the context of that user.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft Word 2016. Specific version ranges are not detailed in the available data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, indicating low current exploitation probability. The vulnerability is not listed in CISA KEV catalog. Based on the description, it is inferred that the attack would require opening a malicious document, implying a local file-based attack vector. While unlikely to be seen in the wild, the potential for local code execution remains a serious risk.
OpenCVE Enrichment