Impact
An out‑of‑bounds read vulnerability in the Graphics Component of Microsoft Office allows an attacker who has local access to read protected data that should not be readable. The flaw does not enable code execution or denial of service; instead it lowers confidentiality of files and data stored on the machine. The weakness is a classic CWE‑125 out‑of‑bounds read.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021 and Microsoft Office LTSC for Mac 2024. No affected-version details are available, so the specific versions impacted are not confirmed.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability is considered moderate in severity. The EPSS score of <1% indicates a low probability that it will be actively exploited, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires local user privileges, meaning an attacker must already have access to the target computer and be able to run Office to trigger the buffer over‑read. In the absence of a remote or privilege‑escalation vector, the overall risk to organizations is modest but non‑negligible, especially where sensitive documents are stored on user‑level machines.
OpenCVE Enrichment