Impact
A heap-based buffer overflow in Microsoft Office Access enables an unauthorized attacker to execute arbitrary code locally, compromising the confidentiality, integrity, and availability of the affected system. The weakness is a classic out-of-bounds write that can overwrite critical memory structures, allowing the attacker to control program flow. The vulnerability is categorized as CWE‑122.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. All versions of these products are potentially vulnerable; the exact affected releases are not listed but the product families are enumerated by the CNA.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while a lack of EPSS data and the absence from the CISA KEV catalog suggest the public exploitation rate is currently unknown. Based on the description, the likely attack vector involves an attacker supplying a malicious Access database or document that, when opened locally, triggers the overflow to execute code on the victim’s machine. The vulnerability can be exploited by unmanaged users who can create or upload a malicious file to a shared location, emphasizing the need for timely remediation.
OpenCVE Enrichment