Impact
A heap‑based buffer overflow in Microsoft Office Word allows an attacker to execute arbitrary code on a vulnerable system. The flaw occurs when a specially crafted document is processed, giving the attacker control over the program’s execution flow. The result is a full compromise of the Office installation, enabling the attacker to run code with the privileges of the current user, potentially escalating privileges or accessing sensitive data. The vulnerability is a classic example of CWE‑122, a heap‑based overflow that can undermine confidentiality, integrity, and availability.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016 are all affected. The data does not specify a limited set of vulnerable patch levels, so the entire product line should be assumed affected until an official update is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available, so the exact likelihood of exploitation cannot be quantified. The KEV status shows the vulnerability is not listed in CISA’s catalog, which suggests no widespread active exploitation has been observed to date. It is inferred that the likely attack vector is remote: an attacker can send a malicious document over a network—such as via email, shared documents, or a compromised website—and rely on the end user to open it. While user environments or anti‑virus tools may provide some defense, the vulnerability can be leveraged on unpatched systems without additional hurdles.
OpenCVE Enrichment