Impact
The vulnerability is a heap‑based buffer overflow that allows an attacker to execute arbitrary code locally. The CVE states that an unauthorized attacker can execute code locally, but it does not specify the privilege level required to run Office. Based on the description, it is inferred that an attacker who succeeds in exploiting the overflow will run code with the same privileges as the Office process, potentially leading to full compromise of confidentiality, integrity, or availability on the affected machine.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific affected versions are not listed in the data, so only product families are identified.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity vulnerability. The EPSS, the probability of exploitation, is low, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the heap overflow could be triggered via a specially crafted Office document or file, and a local attacker could execute code with the privileges of the user. The likely attack vector is local and dependent on user interaction or compromised local files, as inferred from the description that Office must process a vulnerable file to trigger the overflow.
OpenCVE Enrichment