Impact
Microsoft Office Word contains a heap‑based buffer overflow that any attacker can exploit by opening a specially crafted document. The overflow allows execution of arbitrary code with the privileges of the user who opens the file, which can lead to full system compromise. The vulnerability is categorized as CWE‑122.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Word 2016. All listed versions are vulnerable unless they have received the official patch.
Risk and Exploitability
The CVSS score of 8.8 marks the vulnerability as high severity. EPSS data is not available and the CVE is not in the CISA KEV catalog. Based on the description, the likely exploitation path involves an attacker delivering a malicious Word document over a network—such as via email, shared drives, or web download—and the victim opening it. No elevated privileges or local access are required; any active user can be targeted. The impact is immediate compromise of the user’s machine if the code runs.
OpenCVE Enrichment