Impact
A buffer over-read in Microsoft Office Word allows an unauthorized attacker to read memory beyond a valid boundary, potentially exposing data stored in the Office process or the Word document itself. The weakness is consistent with CWE-126.
Affected Systems
All listed Microsoft Office products are affected, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Word 2016. Specific version numbers are not provided in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity while the EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply a crafted Word document over a network—such as via email or file sharing—to trigger the over-read when the document is opened or processed, enabling the disclosure of sensitive information.
OpenCVE Enrichment