Impact
A heap‑based buffer overflow in the Microsoft Office graphics component enables an unauthorized attacker to run arbitrary code with the privileges of the user who opens a malicious file. The flaw originates from improper bounds checking of data stored in the graphics subsystem, leading to uncontrolled memory writes. Successful exploitation could allow the attacker to modify files, inject malware, or take full control of the affected machine without detection.
Affected Systems
The vulnerability affects Microsoft Office products including Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version details are not specified in the advisory; all installations of the listed products are considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS data is not available, so the current likelihood of exploitation cannot be assessed quantitatively. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the attack vector appears to be local: the attacker must deliver a crafted file or document to the victim, either through phishing, drive‑by download, or other local file‑injection methods. Once the file is opened, the buffer overflow can be triggered, leading to code execution.
OpenCVE Enrichment