Impact
An out-of-bounds read flaw exists in Microsoft Office Word that permits an unauthorized local attacker to read data stored in memory beyond the intended buffer. The vulnerability is a classic buffer overread (CWE-125) and can expose sensitive information to the local user, potentially allowing the attacker to recover confidential data, configuration settings, or other memory contents. The impact is limited to local confidentiality loss, but it could compromise privacy and support integrity by revealing sensitive data.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. Version details are not listed beyond the product families, so all releases of these products remain potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker must have local access or be able to execute a malicious Word document on the target system. No public exploit is announced, and the weakness requires the attacker to trigger the read by opening or specifically manipulating a document that triggers the buffer overread.
OpenCVE Enrichment