Impact
A heap-based buffer overflow in Microsoft Office Access enables an unauthorized attacker to execute arbitrary code on a target machine. The vulnerability can compromise confidentiality, integrity, and availability of the affected system, leading to full system takeover if exploited successfully.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. All listed editions are vulnerable unless patched.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score is not available, so precise exploitation probability cannot be measured, but the lack of a KEV listing suggests no widespread exploitation yet. The likely attack vector is over a network, with an attacker delivering a specially crafted Access file to an unauthenticated user. Successful exploitation would allow the attacker to run arbitrary code with the privileges of the victim user.
OpenCVE Enrichment