Impact
Improper null termination occurs during Microsoft Office Word's processing of documents, allowing an unauthenticated local attacker to read data that should not be exposed. This flaw can reveal portions of memory containing sensitive information, leading to a confidentiality compromise. The weakness stems from CWE‑170 related to improper string handling. The base CVSS score of 5.5 reflects a moderate level of risk that warrants attention.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016 (both 32‑bit and 64‑bit Windows versions) and the corresponding Mac editions are affected.
Risk and Exploitability
The vulnerability is exploitable locally and does not require network access. The CVSS base score of 5.5 indicates a moderate severity. EPSS data is not available, so the probability of exploitation remains uncertain. It is not listed in the CISA KEV catalog, implying no known large‑scale exploitation events. Based on the description, it is inferred that an attacker would need a way to cause Word to process malicious or crafted content—such as a document or script—to trigger the improper null termination.
OpenCVE Enrichment