Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office that permits an unauthorized local attacker to read protected memory contents, resulting in disclosure of sensitive data. This weakness is identified as CWE‑125 and represents a classic memory‑unsafe read that leaks information but does not provide code execution or denial of service.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. Version details are not specified in the current data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw requires local access; the attack vector is inferred to involve a local user interacting with Office applications or files. Remote exploitation or privilege escalation is not supported by the supplied data.
OpenCVE Enrichment