Impact
An out-of-bounds read bug in Microsoft Office Word allows an authorized local attacker to read data from memory that should not be exposed, potentially revealing sensitive information such as passwords, cryptographic keys, or other confidential data. The vulnerability is classified as CWE‑125 and does not provide remote code execution or denial of service capabilities. The bug requires the attacker to have a user account on the affected machine and the ability to run Word normally.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016 and their macOS counterparts. Version details are not specified; all recent releases of these products are likely vulnerable.
Risk and Exploitability
The CVSS score of 5 indicates medium overall severity, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires local authorization and does not provide an external attack vector, so the exploitation risk is moderate. The only documented fix is the Microsoft Office update that addresses CVE‑2026‑72976.
OpenCVE Enrichment