Impact
This vulnerability is a stack‑based buffer overflow in Microsoft Office Access that enables an attacker to run arbitrary code when a vulnerable Access file is opened. The flaw can be triggered by a specially crafted Access file and may allow the attacker to hijack control flow, potentially leading to information disclosure or denial of service if the injected code exploits further system components. The weakness is identified as CWE‑121, a classic stack exploit.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (both 32‑bit and other editions), Microsoft Office 2019, Office LTSC 2021, and Office LTSC 2024. The update guide references all these versions; specific sub‑versions are not explicitly listed in the data, so any installation of the listed products is considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS is not available, and the exploit is not listed in CISA’s KEV catalog, implying no known widespread or controlled exploitation as of the data. The likely attack vector is through a malicious Access file opened by a user or via a remote network location. An attacker with local access or one able to deliver a malicious file to a vulnerable client can trigger the overflow and execute code, potentially compromising the local machine.
OpenCVE Enrichment