Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office products that allows an unauthorized local attacker to read sensitive data from memory. This flaw corresponds to CWE‑125 and could lead to disclosure of confidential information such as passwords, personal data, or other secrets held in the Office process. The impact is limited to the local system, without enabling remote code execution or escalation.
Affected Systems
Affected systems include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, Office 365 for Mac, Office LTSC for Mac 2021 and 2024, and Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No specific sub‑version numbers are listed, so all builds under these product lines are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely leveraged. An attacker would need local access to the affected machine, so restricting local user privileges and keeping the software updated are key mitigating strategies.
OpenCVE Enrichment