Impact
Microsoft Office Word contains a heap‑based buffer overflow that allows an unauthorized attacker to execute arbitrary code on an affected system via a maliciously crafted document. This remote code execution flaw has a CVSS score of 8.8, indicating a high severity level. The weakness is classified as CWE‑122 and can compromise confidentiality, integrity, and availability of the victim’s machine.
Affected Systems
The vulnerability affects several Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Word 2016 across Windows and macOS platforms.
Risk and Exploitability
The EPSS score is not available, but the CVSS score indicates a high risk of exploitation if the attacker can deliver a malicious Word document over a network. Based on the description, the likely attack vector involves a network‑shared file or an email attachment that triggers the overflow when opened by the victim. The flaw can be leveraged by an attacker with no privileged access to achieve full code execution, and because the vulnerability is not listed in CISA’s KEV catalog, there are no known active exploits at the time of this analysis.
OpenCVE Enrichment