Impact
The vulnerability is a stack‑based buffer overflow in Microsoft Office Access that allows an unauthorized attacker to execute arbitrary code over a network. This flaw, classified as CWE‑121 and CWE‑20, can compromise confidentiality, integrity, and availability on the affected system if exploited.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. No specific version numbers are listed, but any installation of these packages that has not yet received the latest security update is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the lack of public exploitation evidence does not diminish the risk. The likely attack vector is via a malicious data packet or file delivered over the network, requiring the victim to use Office Access to open the damaged data; therefore, the vulnerability is exploitable remotely without authentication.
OpenCVE Enrichment