Impact
Microsoft Office Access contains a heap‑based buffer overflow that permits an attacker to run arbitrary code locally. The flaw originates when the program processes specially crafted data, allowing the attacker to overwrite critical memory structures and execute malicious instructions. The resulting compromise gives the attacker the same privileges as the user who opens the affected file, enabling the installation of malware, manipulation of data, or further lateral movements within the system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, and the long‑term servicing channel editions of Microsoft Office LTSC 2021 and LTSC 2024 are affected. The vulnerability applies to all builds tracked by Microsoft until an update is applied, as detailed in the Microsoft advisory referenced in the CVE record.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local attackers, while the EPSS score of < 1 % and absence from CISA KEV suggest that public exploitation is currently limited. The likely attack vector is opening a maliciously crafted file with Microsoft Access, a scenario that does not require network access or elevated privileges. Once a user opens such a file, the unchecked memory write can be leveraged to execute code at the user's privilege level. Given the potential impact on confidentiality, integrity, and availability, any environment that accepts untrusted Access files represents a high risk until a fix is applied.
OpenCVE Enrichment