Impact
Microsoft Office contains an out‑of‑bounds read that can be triggered by an unauthorized local attacker to extract data from memory. The flaw maps to CWE‑125 and permits disclosure of sensitive information from the executing process, compromising confidentiality of the user’s data and the system environment.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise as well as Microsoft Office 2016, 2019, 2021, 2024, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021 and Office LTSC for Mac 2024. No specific patch release dates are listed, but any build of these products that has not yet received the security update is susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, and the description indicates that exploitation requires local privilege or access. Consequently, the risk remains limited to attackers who can run code locally on an affected device; remote exploitation is not supported by the current data.
OpenCVE Enrichment