Impact
An out‑of‑bounds read flaw in Microsoft Office Word enables an attacker to read memory beyond the intended bounds of the application, exposing local data such as documents or user credentials. This is a classic information‑disclosure vulnerability classified as CWE‑125. The effect is limited to data already present on the targeted system and does not grant the attacker additional privileges or remote control.
Affected Systems
The vulnerability affects multiple Microsoft Office products across Windows and macOS, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Word 2016. Specific version numbers are not specified in the available data.
Risk and Exploitability
The CVSS score of 5.5 places this flaw in the medium severity range, while an EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must have local access or be able to tamper with a Word file they can run on the victim’s machine; remote exploitation is not supported by the description. Despite the moderate score, applying the vendor’s fix remains advisable to preclude potential data leaks.
OpenCVE Enrichment