Impact
A heap‑based buffer overflow exists in Microsoft Office Word that can be triggered by an attacker to execute arbitrary code on the local machine. The flaw arises when Word processes a crafted document or element, allowing the attacker to gain full control of the affected process with the user’s privileges.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Outlook 2016 across both Windows and macOS platforms. Version information was not provided.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is considered high severity. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a very low probability of exploitation in the current threat landscape. Based on the description, it is inferred that the attack vector involves an unauthorized local user or an attacker who can supply a crafted document that Word processes, allowing execution of code with the user’s privileges. The absence of a publicly known exploit does not eliminate risk, especially for systems handling untrusted content.
OpenCVE Enrichment