Impact
A heap‑based buffer overflow has been identified in the Microsoft Office graphics component. An attacker who can supply crafted input while the Office application is running can trigger the overflow and execute arbitrary code locally on the target system. The vulnerability is a classic CWE‑122 flaw that allows local adversaries to compromise confidentiality, integrity, and availability of the affected Office instance.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021 LTSC, Microsoft Office 2024 LTSC, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version details are not published, so all releases under those product families are treated as at risk until the next patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity and the EPSS score is currently not available, suggesting that no public exploit has been observed to date. The vulnerability is not listed in the CISA KEV catalog, implying that it may not yet be actively weaponized. Nonetheless, the local nature of the attack suggests that privileged or authenticated users, or anyone capable of creating a malicious Office document, can exploit this flaw. The attack vector is inferred to be local, triggered by processing crafted inputs within the Office graphics subsystem.
OpenCVE Enrichment