Impact
An out‑of‑bounds read bug in Microsoft Office products allows an unauthorized attacker to read memory beyond intended limits, exposing sensitive data across a network. The flaw matches CWE‑125 and results in a confidentiality breach by leaking arbitrary information from the victim's memory.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 are impacted. Specific version details are not listed.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity. No EPSS score is provided, so exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploited instances. The likely attack vector appears to be network‑based, as the disclosure can occur over a network. An attacker would need to supply or otherwise interact with Office in a way that triggers the out‑of‑bounds read. The risk to an organization depends on Office exposure to untrusted networks or users but is mitigated by the absence of known exploits. Applying the patch reduces the threat to a minimal residual risk.
OpenCVE Enrichment