Impact
The flaw is a stack‑based buffer overflow in the Microsoft Office graphics component, falling under CWE‑121. An attacker who can supply crafted input to an Office file can overflow the stack and execute arbitrary code within the Office process. Because the code runs under the user’s privileges, the impact can extend from local privilege escalation to full system compromise if the user possesses administrative rights. The vulnerability is documented as a local code‑execution flaw.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Office 2019, Office 2021, Office 2024, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024 are all affected irrespective of deployment mode.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. No EPSS score is available, so the present exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not a widely exploited or active risk at present. The attack vector is local; an adversary requires to distribute or trick a user into opening a malicious Office file that triggers the stack overflow, after which arbitrary code runs with the user’s rights.
OpenCVE Enrichment