Impact
A stack-based buffer overflow in Microsoft Office Word permits an unauthorized attacker to execute arbitrary code over a network. This vulnerability, identified as CWE‑121, enables the attacker to compromise the confidential integrity and availability of the affected system.
Affected Systems
The issue affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. No specific version ranges are listed, implying the reported builds are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the lack of an EPSS score means we cannot quantify probability but the vulnerability is not recorded in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is network‑based, allowing an attacker to trigger the overflow by sending malicious content to a remote user’s Office application.
OpenCVE Enrichment