Impact
Heap-based buffer overflow in Microsoft Account permits an attacker who can reach the service over a network to execute arbitrary code with the privileges of the account service.
Affected Systems
The vulnerability impacts the Microsoft Account product, but no specific affected versions are disclosed by the CNA. Administrators should verify the patch status of all Microsoft Account deployments regardless of the environment, as the data does not delineate which releases are affected.
Risk and Exploitability
The CVSS score of 9.8 flags critical severity, while the EPSS score of less than 1 % indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, remote code execution could compromise system integrity and availability if an attacker succeeds. The attack vector is inferred to be remote, network‑based communication toward the Microsoft Account service, based on the description that the overflow is exploitable over a network.
OpenCVE Enrichment