Impact
A numeric truncation error in Microsoft Office Word, classified as CWE‑197, enables an unauthorized attacker to execute code locally on the affected machine. The flaw could lead to arbitrary code execution with the privileges of the current user, compromising the confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability impacts Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016, as listed by the CNA as affected.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score is not available, so the exploitation probability is currently unknown, although the issue is not listed in the CISA KEV catalog. The description does not provide a specific trigger; based on the nature of Word vulnerabilities, it is inferred that a malicious document or macro could be used to exploit the numeric truncation, but the exact vector is not specified. Without remediation, any user who activates the flaw may gain full control of the system.
OpenCVE Enrichment