Impact
An out‑of‑bounds read (CWE-125) in the Microsoft Office graphics component allows an attacker to read memory that should be inaccessible. The vulnerability can expose sensitive data from the local system, potentially undermining confidentiality for any user who runs the affected Office product. The description does not indicate any escalation of privileges beyond the current user account, so the impact is limited to information disclosure rather than execution or control of the system.
Affected Systems
This flaw affects several Microsoft Office distributions, including Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Microsoft Word 2016. All releases of these products are potentially vulnerable until a security update is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and no EPSS score is available, suggesting that the exploitation probability is currently unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the supplied information, the likely attack vector is local: a user must run a specially crafted Office document or component on a compromised or malicious system to trigger the out‑of‑bounds read. Without an active local user context, the flaw cannot be exploited remotely.
OpenCVE Enrichment