Impact
An out‑of‑bounds read in Microsoft Office Word enables a local attacker to access sensitive data that should not be exposed. The vulnerability is a CWE‑125 flaw that can leak information inside the process memory of Word, potentially revealing confidential documents or system secrets. The impact is limited to local information disclosure, not remote code execution or denial of service.
Affected Systems
The flaw affects Microsoft Word 2016, Office 2019, Office LTSC 2021 and 2024, Microsoft 365 Apps for Enterprise, and Office 365 for Mac, including the LTSC and Mac variants released in 2021 and 2024. These are all Microsoft Office installations on Windows or macOS.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS shows a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an adversary must have access to the target machine or be able to trick a user into opening a malicious document. Under these conditions the risk is moderate but low likelihood, and no advanced remote exploitation is required.
OpenCVE Enrichment