Impact
Microsoft Office contains an improper input validation flaw that permits an unauthorized local attacker to access privileged or confidential data on a system, resulting in disclosure of sensitive information without authentication. The weakness is classified as CWE‑20, indicating that user‑supplied data is not adequately validated.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version exclusions are listed, implying that current releases are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1% shows that exploitation attempts are expected to be rare. The vulnerability is not listed in the CISA KEV catalog, further indicating low exploitation pressure. Based on the description, the likely attack vector is local access; an attacker must be able to execute or supply crafted input on the target machine to trigger the information disclosure.
OpenCVE Enrichment