Impact
Improper input validation in Microsoft Office enables an unauthorized local attacker to access and expose confidential information stored on the affected system. This leads to a loss of confidentiality for user documents and related data, and represents a classic CWE‑20 problem of an inadequate validation of user-supplied input.
Affected Systems
Microsoft 365 Apps for Enterprise; Microsoft Office 2019; Microsoft Office 365 for Mac; Microsoft Office LTSC 2021; Microsoft Office LTSC 2024; Microsoft Office LTSC for Mac 2021; Microsoft Office LTSC for Mac 2024. All provided product families are affected, but the specific patched versions are not disclosed in the available data.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate severity, while the EPSS score is less than 1%, suggesting a very low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalogue. The attack vector is local: an attacker with local system access must meet the precondition of entering Microsoft Office input that is not properly validated to trigger the disclosure. No publicly known exploit has been reported beyond this advising context.
OpenCVE Enrichment