Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office Access that allows an unauthorized attacker to execute code remotely. This flaw can lead to complete compromise of the affected system, providing the attacker with the same privileges as the user running the Office application. The weakness is identified as CWE‑122.
Affected Systems
Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, Microsoft 365 Apps for Enterprise, and Microsoft Access 2016 (32‑bit edition). Specific affected versions are not listed.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. The EPSS score is not available, so the current predicted likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, but the attack vector is inferred to be remote over a network. If an attacker can deliver malicious content to a vulnerable client, code execution can occur without user interaction.
OpenCVE Enrichment