Impact
The vulnerability arises from the use of an uninitialized resource in Microsoft Office, allowing an attacker with local access to read data that should not be exposed. This falls under CWE‑908 and can reveal confidential content such as documents, credentials, or user data. The immediate impact is a breach of confidentiality for information accessed by the Office process.
Affected Systems
Affected editions include Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and the corresponding Mac versions of LTSC 2021 and LTSC 2024.
Risk and Exploitability
The CVSS score of 5.5 denotes moderate severity, yet the EPSS score is below 1 %, indicating a low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Attackers must already be present locally or have malware running on the target machine; no external network attack is required.
OpenCVE Enrichment