Impact
Microsoft Office has a vulnerability involving improper neutralization of special elements used in a command, which enables a command‑injection flaw. An attacker who can supply a specially crafted Office document or exploit a local Office instance may cause the application to execute arbitrary code on the affected system. The flaw could result in full compromise of the user’s machine, allowing an attacker to steal data, modify files, or covertly install additional malware. The weakness is classified as CWE‑77, representing an injection vulnerability.
Affected Systems
The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. No specific sub‑version data is listed, indicating that all released versions of these products are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity flaw, and the EPSS score is not available, so the current exploitation probability is undefined. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or network‑based delivery of a malicious Office file that an unauthorized user can open. Once executed, the command‑injection flaw can allow code to run with the privileges of the Office process and potentially the current user.
OpenCVE Enrichment