Impact
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute arbitrary code on the host with the privileges of the user running the application. This flaw enables local code execution, potentially leading to full compromise of the affected system if the attacker can persuade a user to open a malicious file or otherwise trigger the overflow. The vulnerability is rooted in CWE-122 and is similar to other uncontrolled heap writes seen in Office components.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. Specific affected versions are not enumerated in the CNA data, so all currently available builds of these products should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity, indicating a substantial impact if exploited. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so its exploitability in the wild is unknown. The likely attack vector is local; an attacker needs to convince a user to open a crafted file or otherwise trigger the overflow. Because the flaw results in code execution, any successful exploitation could allow an attacker to gain the privileges of the logged‑in user.
OpenCVE Enrichment