Impact
A heap‑based buffer overflow in Microsoft Office Word enables an attacker with remote network access to execute arbitrary code within the context of the vulnerable application. This vulnerability can lead to complete compromise of the user’s device, allowing the attacker to steal data, modify files, or launch further attacks on the network. The weakness corresponds to CWE‑122, indicating improper handling of heap memory boundaries.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. Version details are not specified; all current releases of these products are considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as critical, but the EPSS score is not available, indicating no current public exploitation data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be remote network based on the description of code execution over a network; an attacker would need to deliver a malicious document or payload to a victim system.
OpenCVE Enrichment