Impact
An out‑of‑bounds read vulnerability exists in Microsoft Office Word that allows an attacker with local access to read memory contents that should be inaccessible. The flaw permits disclosure of data contained in the application's process memory or in an Office document, resulting in local information leakage. No remote or privilege escalation capability is indicated in the description.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and 2024, Microsoft Office LTSC for Mac 2021 and 2024, and Microsoft Word 2016 on Windows and macOS. The CNA does not list specific version numbers, implying the issue spans all publicly available releases of these products until the update is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. Because the flaw requires the attacker to be already logged in locally, exploitation opportunities are limited to compromised user contexts. The impact is confined to confidentiality of information visible to the local user and does not provide direct system integrity or availability damage.
OpenCVE Enrichment