Impact
An out-of-bounds read in Microsoft Office permits a local, unauthorized attacker to read memory data that could contain sensitive information, resulting in information disclosure from the victim’s machine. The weakness is a classic CWE-125 flaw where bounds checks are insufficient before accessing data structures. The impact is limited to compromising the confidentiality of data accessible by the logged‑in user but does not provide remote code execution or privilege escalation.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024 are listed as vulnerable. Specific version details are not supplied, so all installed instances of these products should be considered at risk if updates are not applied.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range. EPSS is not available, making it unclear how often attackers attempt exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local; an attacker must have physical or software access to the target machine and be able to trigger the out-of-bounds read. Consequently, the risk is moderate but warrants remediation to prevent accidental or intentional disclosure.
OpenCVE Enrichment