Impact
A heap-based buffer overflow exists in the Microsoft Office graphics component. Unauthorized users can trigger the overflow to run arbitrary code locally on the affected system, compromising confidentiality, integrity, or availability of data processed by Office applications. The weakness corresponds to CWE‑122, a heap memory corruption flaw. No remote exploitation is documented in the CVE description.
Affected Systems
Microsoft products including Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are all vulnerable in their current builds unless updated.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% signals a very low but not negligible probability of exploitation in the current environment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local access: an attacker must deliver a malicious Office file or graphic to a user’s machine, causing the overflow during rendering. Because the exploit requires local interaction, the risk is limited to environments where users can open files from untrusted or compromised sources. However, once the overflow is triggered, an attacker could gain code execution with the privileges of the Office process, which may elevate to higher privileges if the process is privileged or if privilege escalation paths exist.
OpenCVE Enrichment