Impact
This vulnerability is an out‑of‑bounds read (CWE‑125) in Microsoft Office that allows an unauthorized attacker to read memory or local files not intended for disclosure. The flaw can lead to the exposure of sensitive documents, configuration files, or other data stored on the compromised machine.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All installed builds of these products may be affected; no specific version exclusions are documented.
Risk and Exploitability
Based on the description, it is inferred that the attacker must already have local system access to exploit this flaw. The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the broader ecosystem, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, organizations should consider the potential for accidental or intentional data leakage as a moderate risk and prioritize timely remediation.
OpenCVE Enrichment