Impact
A heap‑based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute arbitrary code without local privileges. When a specially crafted Word document is opened, the flaw can be triggered over a network, compromising the confidentiality, integrity, and availability of the affected system. The vulnerability is identified as CWE‑122, indicating an unsafe handling of heap memory that can lead to code execution. The primary impact is the potential for a remote attacker to run unauthorized instructions on the victim machine.
Affected Systems
The flaw affects multiple Microsoft Office product lines, including Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024, Office for Mac 2021, Office for Mac 2024, Office 2016, and their corresponding Mac and Exchange‑based variants. Any installation of these products that has not incorporated the latest security update from Microsoft is potentially exposed.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. Because the EPSS score is not available, the precise exploitation probability is unknown, yet the flaw is not listed in the CISA KEV catalog, indicating no documented widespread exploitation to date. The likely attack vector is a network‑based delivery of a maliciously crafted Word document, with no authentication required. Given these factors, the risk to organizations remains significant while exploitation remains theoretically possible.
OpenCVE Enrichment