Impact
A heap-based buffer overflow exists in various versions of Microsoft Office. The weakness allows an attacker who can supply a crafted document or data stream over a network to overwrite memory and execute arbitrary code. The primary consequence is full remote code execution with the privileges of the user running Office, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. Specific patch‐level or release identifiers are not supplied in the CNA data, so all deployed instances of these products are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so the current exploitation likelihood is uncertain. The attack vector is inferred to be network‑based, likely through a malicious document sent via email or shared over a network drive, which leverages the heap overflow to gain code execution.
OpenCVE Enrichment