Impact
A heap‑based buffer overflow in Microsoft Office Word permits a locally‑present attacker to read memory contents and reveal sensitive data that could be stored in the document or in user context. The flaw results in information disclosure but does not provide code execution or privilege escalation, and it requires the attacker to have local access to the affected system.
Affected Systems
The vulnerability affects multiple Microsoft Office releases, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 365 for Mac, the long‑term servicing channel (LTSC) editions 2021 and 2024 for both Windows and Mac, and Microsoft Word 2016. Users running any of these products are potentially exposed if the software has not been updated.
Risk and Exploitability
The CVSS base score of 5.5 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the issue is not listed in CISA's KEV catalog. The flaw requires local execution, meaning the attacker must already have some presence on the target machine. Because the impact is limited to information disclosure and the exploitation vector is local, the overall risk is moderate but warrants timely patching to preclude disclosure of confidential data.
OpenCVE Enrichment