Impact
Improper input validation in Microsoft Office Word lets an attacker running on the same machine read sensitive data. The flaw does not enable remote execution or privilege escalation; it merely exposes confidential information stored locally. The vulnerability is classified as CWE‑20, reflecting a failure to properly restrict inputs. The effect is a confidentiality breach if an unauthorized local user can trigger the defect.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024 are all affected. Version specifics are not listed, but the issue applies across the documented product families.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity, and the EPSS score is below 1 %, suggesting a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to be able to run code on the local system and supply crafted input to Word; no network or privilege escalation vector is described.
OpenCVE Enrichment