Impact
The vulnerability is a stack‑based buffer overflow that occurs when Microsoft Office Word processes certain document data. This flaw, designated CWE‑121, permits an attacker to corrupt the call stack and inject executable payloads, enabling arbitrary code execution on the victim’s machine. The impact is that any code running under the user’s account could be exploited, affecting confidentiality, integrity, and availability of the local system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, Word 2016, SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No specific patch versions are listed, but all known editions of these products are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is a malicious Word document that a user opens, such as one delivered via email, shared network location, or web‑hosted file. In this scenario, the stack overflow would trigger when the document content is rendered, allowing the attacker to execute code locally.
OpenCVE Enrichment