Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office Word (CWE‑125). An attacker who can trigger the defect can read memory beyond the intended buffer, resulting in the disclosure of sensitive information. The primary impact is the leakage of confidential data that may belong to documents, system memory, or other secrets handled by Word.
Affected Systems
The issue affects multiple Microsoft Office products across Windows and macOS. Specifically, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. All referenced versions are impacted; no finer version granularity is provided in the available records.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium‑severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, implying no known large‑scale exploitation to date. The defect is likely exploitable over a network connection, with an attacker able to supply a malicious document or otherwise interact with Word remotely to trigger the out‑of‑bounds read. The overall risk is moderate, but organizations should treat it as a potential information disclosure threat until a patch is applied.
OpenCVE Enrichment