Impact
A heap-based buffer overflow exists in Microsoft Office Word that permits an unauthorized attacker to execute arbitrary code locally on the victim machine. The flaw arises when Office processes malformed content, leading to memory corruption that can be exploited to launch code with the privileges of the current user. This vulnerability directly threatens confidentiality, integrity, and availability of the affected system by allowing attacker‑supplied code to run with user‑level rights.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. While the exact service pack or build numbers are not specified, any installation of these Office suites that has not been updated after the release of CVE‑2026‑64915 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of <1% indicates a very low probability of exploitation; combined with the high CVSS and no KEV listing, this suggests limited but potentially serious risk pending local code execution. The lack of KEV assignment implies no widespread, documented exploitation to date. Based on the description, the likely attack vector is via a malicious Office document that a user opens, inferred from the local code execution outcome. Given the high impact and the possibility of user interaction, this vulnerability represents a significant risk to any unpatched system.
OpenCVE Enrichment