Impact
A heap-based buffer overflow exists in Microsoft Office Word that permits an unauthorized attacker to execute code remotely by exploiting problematic memory handling. The flaw is classified as CWE‑122 and can lead to full compromise of the affected system, including execution of arbitrary code with the privileges of the user who opens the vulnerable document.
Affected Systems
The vulnerability affects multiple Microsoft Windows platforms, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and a range of Windows Server releases from 2012 through 2025. Updated operating systems within these families must be examined for the presence of the associated security update.
Risk and Exploitability
The CVSS score of 8.8 places this flaw in the High severity range. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, implying no widely known exploitation yet. The likely attack vector is remote, involving the delivery or opening of a malicious Word document over a network; however, this is inferred from the description and not explicitly detailed in the data. The absence of a public exploit does not diminish the need for timely remediation, as the high severity indicates significant potential impact.
OpenCVE Enrichment