Impact
This vulnerability is a heap‑based buffer overflow in Microsoft Office that enables an attacker who can provide a specially crafted document over a network to execute arbitrary code. The overflow occurs during document processing, allowing the attacker to influence the memory layout within the Office process and inject executable payloads that run with the privileges of the launching user. Such code execution can compromise confidentiality, integrity, and availability of the affected system, and can be used to deliver malware or steal data.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and their macOS counterparts (Office LTSC for Mac 2021 and 2024). The specific vulnerable versions are not listed in the available data, so the scope of vulnerable releases cannot be confirmed beyond these product lines.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity, and the EPSS score of less than 1% indicates a very low exploitation probability. It is not currently listed in the CISA KEV catalog, indicating no publicly known active exploitation at the time of analysis. The likely attack vector is via a network source sending a malicious document that is opened or opened automatically, requiring the victim to have Office installed and be able to receive the crafted file. The attacker must be able to insert the malformed payload into a document that Office processes, after which the overflow triggers code execution.
OpenCVE Enrichment