Impact
A numeric truncation error present in Microsoft Office Word enables an unauthorized attacker who can exercise local privileges to obtain confidential data. The flaw allows the disclosure of information that should be protected, resulting in a breach of confidentiality while not affecting integrity or availability.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft Word 2016 are affected. Specific version ranges were not supplied, so all unpatched versions of these products are considered vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is local; an attacker must be able to run code on the target system or otherwise interact with the Office application to trigger the truncation error. The vulnerability is not listed in the CISA KEV catalog, so no publicly tracked exploit is known.
OpenCVE Enrichment