Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office Word that allows an attacker to execute code on a local system. An unauthorized user can craft a malicious document that, when opened, triggers the overflow and gives the attacker full control over the affected machine, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are all impacted. Specific version details are not listed, so all current releases of these products are assumed vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of local code execution. With no EPSS score provided, the exploitation probability is uncertain, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a malicious Word file delivered via email or other media; the attacker must get the victim to open the file, after which the heap overflow can be triggered.
OpenCVE Enrichment