Impact
A stack‑based buffer overflow in the Microsoft Graphics Component allows an unauthorized attacker to execute arbitrary code over a network. Because this flaw lies in a core component of Office, successful exploitation can result in full compromise of the affected system, granting the attacker full control over the application and potentially the underlying operating system. The vulnerability is identified by CWE‑121, reflecting a classic stack corruption issue.
Affected Systems
The flaw affects Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office for Android. No product version ranges are supplied, so any installation of these editions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity weakness. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, so the current exploitation probability is unclear. Nonetheless, the flaw requires only network connectivity to the Office application, making it amenable to remote exploitation from an external host. Administrators should therefore treat this vulnerability as high‑risk and prioritize mitigation.
OpenCVE Enrichment