Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office Access that can be triggered when a malicious Access file is opened. It allows an attacker to execute arbitrary code locally on the victim’s machine and is identified as CWE‑122. No additional escalation beyond the privileges of the user is explicitly stated.
Affected Systems
Affected vendors include Microsoft. Products impacted are Microsoft 365 Apps for Enterprise, Microsoft Access 2016, Microsoft Access 2016 (32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. Any installation of these product lines may be vulnerable when an Access database is opened, as no specific version information is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, but the EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a crafted Access file that the victim opens, leading to local code execution, based on the description of a heap-based buffer overflow.
OpenCVE Enrichment