Impact
The flaw is an off‑by‑one error in Microsoft Office Word that permits an attacker to read data beyond intended bounds, potentially exposing sensitive information stored on the system. Because the bug relates to an out‑of‑bounds read, it is classified under CWE‑125 and CWE‑193, while the improper certificate validation issue (CWE‑295) indicates that data that should be protected could be accessed inadvertently. The impact of successfully exploiting the vulnerability is privilege‑agnostic information leakage; confidential documents or user data may be exposed to any user who can execute or influence Word locally.
Affected Systems
Vulnerable installations include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016. All versions prior to the latest available update that contains the fix for the off‑by‑one boundary check are affected.
Risk and Exploitability
The CVSS score of 5.5 places the issue in the moderate range. The EPSS score of less than 1 % suggests that the probability of exploitation is low, but the vulnerability can be triggered locally by an attacker with the ability to run code in Word. The bug is not listed in CISA KEV, reflecting limited field exploitation at the time of analysis. The most likely attack vector is a local user or application that can open a crafted document or otherwise exercise the faulty code path in Word.
OpenCVE Enrichment