Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office Word that can allow an attacker who supplies a malicious document to read data that should not be accessible. The primary consequence is the unintended disclosure of potentially sensitive information to the attacker. The weakness is classified as CWE‑125, a classic out‑of‑bounds read flaw that compromises confidentiality rather than enabling arbitrary code execution or denial of service.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Microsoft Word 2016 across Windows and macOS platforms. No specific version ranges are listed, so all current releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation is not documented. The likely attack vector is local or via network delivery of a crafted Office file, inferred from the description that an unauthorized attacker can disclose information over a network. No conditions beyond delivering the malicious file are mentioned, so the vulnerability is exploitable as soon as the user opens or processes the file.
OpenCVE Enrichment