Impact
An out‑of‑bounds read flaw in Microsoft Office Word allows an attacker who can locally execute or instruct the application to process a crafted document to read memory contents that should be protected. This abuse of inadequate boundary checks is a CWE‑125 vulnerability and can reveal whatever data resides in the accessed memory at run time, potentially including sensitive or confidential information. The impact is limited to disclosure of information; it does not modify data or grant control over the system.
Affected Systems
The flaw affects all current releases of Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016, as listed by the CNA. Without specific version ranges the safest assumption is that every shipped version remains vulnerable until the Microsoft security update is applied.
Risk and Exploitability
With a CVSS base score of 5.5 the issue is assessed as moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating low public exploitation risk. The likely attack vector is local; an attacker needs either local access or to convince a user to open a malicious document that triggers the out‑of‑bounds read when Word processes it. Because the flaw only allows reads, non‑privileged local execution is sufficient to obtain the disclosed information, but no privileged escalation or remote code execution is possible.
OpenCVE Enrichment