Impact
The vulnerability involves improper neutralization of special elements used in a command, allowing a command injection flaw in Microsoft Office. An authorized local user who can produce or modify Office documents may exploit this weakness to execute arbitrary commands under the application's user context, thereby elevating privileges on the host system. The flaw is described by CWE‑77 and can lead to a compromise of confidentiality, integrity, or availability if the attacker gains elevated rights.
Affected Systems
Affected installations include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. No specific version ranges are listed, so all instances of these products are considered vulnerable until updated.
Risk and Exploitability
With a CVSS score of 7.8, the threat is classified as high severity. The EPSS score is not available, so the current probability of exploitation is unknown, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker who already has read/write access to Office files can craft a malicious package that triggers the command injection, chaining it to privilege escalation on the target machine.
OpenCVE Enrichment