Impact
A vulnerability in Microsoft Office applications permits an attacker to trigger an integer underflow that leads to arbitrary code execution with the privileges of the user. The flaw maps to CWE-122, CWE-125, and CWE-191 and allows a local attacker to execute code on the system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. The vulnerability exists in both Windows and macOS builds; specific patch levels are not enumerated in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high impact, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker supplying a crafted Office file that, when opened by a user, causes the integer underflow and invokes arbitrary code. No public exploit has yet been confirmed, but the nature of the flaw permits local privilege escalation if the document is accessed by an infected user.
OpenCVE Enrichment