Impact
The vulnerability is a stack‑based buffer overflow in Microsoft Office’s graphics component. An attacker who can provide a crafted file to the affected Office application can trigger the overflow and execute arbitrary code on the local machine. This flaw falls under CWE‑121 and CWE‑79 and can compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected systems include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and the Mac equivalents of the LTSC releases. No specific version details are supplied in the advisory, so any installation of these products issued before the MSRC patch is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks the flaw as high severity. The EPSS score is reported as < 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV collection. The attack vector appears to be local; an attacker needs to provide a malicious Office document or image that triggers the graphics component processing.
OpenCVE Enrichment