Impact
A stack‑based buffer overflow in Microsoft Office Access permits an unauthorized attacker who can supply malicious input to execute arbitrary code on the local machine. The vulnerability, classified as CWE‑121, enables exploitation of Access database files or related components so that the attacker can run code with the privileges of the logged‑in user. The impact, therefore, is local execution of malicious payloads, potentially including privilege escalation if the account is privileged. The CVE description confirms that execution occurs locally, indicating that the attack requires local access or user interaction with a vulnerable Access file.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. No specific version subranges are listed in the CNA data, so all current releases of these products are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity vulnerability. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known prevalent exploits at this time. Based on the description, the likely attack vector is local – an attacker who can trick a user into opening a malicious Access file or supply crafted data to a vulnerable component. If the vulnerability were exploited, it could lead to execution of code with user privileges and potentially elevate to higher privileges, depending on the target account.
OpenCVE Enrichment