Impact
A bug in Microsoft Office permits an out‑of‑bounds read that can be triggered by reading data beyond intended memory or file boundaries, potentially exposing sensitive information stored on the system. The vulnerability is categorized as CWE‑125 and does not provide any code execution or remote reach.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All Windows and macOS installations of these products are vulnerable. Specific version information is not provided in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. An EPSS below 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local access to the Office installation. The impact is limited to information disclosure.
OpenCVE Enrichment