Impact
This vulnerability is a buffer over-read flaw residing in Microsoft Office’s handling of certain data structures. An attacker who can cause Office to process crafted input can read beyond the intended memory bounds and obtain sensitive data over a network. The weakness is classified as CWE‑126, an uncontrolled buffer over-read, which enables an unauthorized party to leak confidential information. The potential impact is the exposure of internal data, possibly including user documents, credentials, or other sensitive material, thereby compromising confidentiality but not system integrity or availability.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version ranges are supplied, so all mentioned releases are potentially impacted until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 6.5 categorizes this issue as a medium severity vulnerability. The EPSS score is not available, so the probability of exploitation by an adversary remains unclear but the lack of assistance from active exploits suggests it may not be widely leveraged. The vulnerability is not listed in the CISA KEV catalog, indicating it is not known to have active exploitation in the wild. Attackers are presumed to exploit the flaw over a network by creating specially crafted Office content that triggers the over-read, given the nature of the vulnerability.
OpenCVE Enrichment