Impact
The vulnerability is a stack‑based buffer overflow in Microsoft Office Word. An attacker who can prompt Word to process a specially crafted input can cause the program to execute arbitrary code. The weakness is classified as CWE‑121 and can lead to remote code execution with the privileges of the user running Word, providing full control over the affected system. No additional exploitation steps are disclosed.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. Version specifics are not disclosed in the public advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, but the high CVSS suggests that exploitation could be valuable. Attackers are likely to trigger the overflow through a malicious document or network‑based file that Word processes, so the vulnerability is remotely exploitable over a network. The attack vector is inferred from the description that execution can occur over a network; no other prerequisites are stated in the advisory.
OpenCVE Enrichment