Impact
A heap‑based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. The flaw arises from improper bounds checking and arithmetic miscalculations, as identified by CWE‑122 and CWE‑190. Successful exploitation would give the attacker the privileges of the user who opens the vulnerable file, letting them compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected Microsoft Office products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The CVE does not list specific patch versions, so any release containing the identified code paths is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks this issue as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a maliciously crafted Office document or attachment that, when opened by a user on a local machine, triggers the overflow and runs attacker‑controlled code. The exploitation occurs entirely in user‑mode memory, so privilege escalation beyond the current user is not required. These attack‑vector inferences are not explicitly stated in the input and are derived from the available description.
OpenCVE Enrichment