Impact
A heap‑based buffer overflow in Microsoft Office enables an unauthorized attacker to execute code locally. The flaw could be triggered by crafted Office documents, leading to remote code execution under the privileges of the current user.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office LTSC 2021, and Office LTSC 2024 for Windows. The specific affected editions are those listed under the Microsoft CNA vendors/products.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires the user to open a malicious Office file or document, meaning that users who inadvertently process untrusted documents are at risk. Because the flaw allows arbitrary code execution, the impact could range from data disclosure to full system compromise, depending on the attacker’s payload and the user’s privileges.
OpenCVE Enrichment