Impact
Microsoft Office Publisher has an integer overflow or wraparound bug that permits an unauthorized attacker to run arbitrary code. The flaw is triggered when the application processes specially crafted input, which can be transmitted over a network. An attacker who can supply such input can gain code execution privilege, compromising confidentiality, integrity and availability of the affected system.
Affected Systems
The vulnerability affects Microsoft’s Office suite, specifically Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft Publisher 2016. The advisory does not list particular build or patch levels, so any installation of the above products that has not received the latest security update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while an EPSS score is not available, the lack of a KEV listing suggests that widespread exploitation has not yet been reported. The attack vector is network‑based; an attacker must deliver the crafted payload to a target machine running Publisher. Successful exploitation would allow remote code execution with the privileges of the document author or the user profile in which the application is running.
OpenCVE Enrichment