Impact
An untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally on a compromised system. The flaw permits arbitrary local code execution, giving the attacker the same privileges as the user running the Office application.
Affected Systems
The vulnerability affects all releases of Microsoft Office listed by Microsoft, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. The affected versions are all currently available releases of these products; further version details are not specified.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of potential impact, while the EPSS score is < 1%, suggesting limited publicly known exploitation data. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local code execution, an attacker must first deliver a malicious document or otherwise engage the Office application on the target machine; therefore, remote exploitation is not directly supported by the available data. The risk remains significant for users running unpatched Office installations in environments with untrusted content exposure.
OpenCVE Enrichment