Impact
A heap-based buffer overflow (CWE-122) in Microsoft Office lets an attacker who can deliver malicious content to a user execute arbitrary code on the target machine. The flaw would enable the attacker to run code with the privileges of the logged‑in user, potentially compromising all documents and data accessible to that account.
Affected Systems
Microsoft Office 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 are all affected. Specific patched versions are not listed in the CVE data; any installation of these Office suites vulnerable to the bug should be treated as at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability, but the EPSS probability of <1% shows it is unlikely to be widely exploited today, and it is not yet listed in the CISA KEV catalog. Attackers would likely need to persuade a user to open a crafted Office document or otherwise run malicious code locally, so exploitation requires a user interaction scenario. Given the high impact, defensive measures are still strongly advised.
OpenCVE Enrichment