Impact
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. The flaw can lead to remote code execution, permitting the attacker to run arbitrary code with the privileges of the account that opens the vulnerable document. This weakness is classified as CWE-121.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Word 2016. All listed versions of these applications are impacted by the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity of the issue. EPSS data shows a score of < 1%, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The description indicates that the attack vector is over a network, where an attacker can send a crafted Word file that triggers the stack-based buffer overflow. No specific exploitation prerequisites are enumerated beyond the need for an unauthorized attacker to deliver the malicious document to a vulnerable system.
OpenCVE Enrichment