Impact
This vulnerability is a type‑confusion flaw (CWE‑843) in Microsoft Office that allows an unauthorized attacker to execute code locally on an affected system. By supplying specially crafted input that the Office components treat as an incompatible type, the attacker can gain code‑execution authority with the privileges of the current user. This can lead to data disclosure, credential theft, or further compromise of the machine.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and their Mac counterparts (LTSC 2021 and LTSC 2024 for Mac). The vulnerability applies across the listed Windows and macOS client versions, as indicated by the CPE entries. No specific version numbers are provided in the CNA data, so all releases within the scopes are considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity. EPSS is not available, so the current exploitation probability is unknown but not documented as already exploited; the vulnerability is also not listed in the CISA KEV catalog. The likely attack vector is a malicious Office document or content that the user opens or a plugin that feeds incompatible data to Office. An attacker must be able to supply that input on the victim’s machine; remote delivery may be possible if the victim downloads a crafted file. Because the impact is local code execution, a compromised user account or shared network drive can be used to deliver the payload. The overall risk is therefore moderate to high, especially in environments where users frequently open untrusted documents.
OpenCVE Enrichment