Impact
A use‑after‑free flaw in Microsoft Office Word allows an unauthorized attacker to execute arbitrary code when a specially crafted document is opened. This vulnerability is classified as CWE‑416, a memory corruption weakness that can lead to full system compromise if an attacker gains execution control. The exploitation of this flaw would allow the attacker to run code with the privileges of the user opening the document, potentially escalating to higher privileges depending on the environment.
Affected Systems
Affected by the list of Microsoft products including Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version numbers are provided, so all releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 marks this as high severity. While the EPSS score is not available, the lack of an exploit listed in KEV suggests it has not yet been widely exploited in the wild. The vulnerability is exploitable over a network when an adversary can deliver a malicious Word file to a user, implying a network attack vector. With a high severity score and a straightforward exploitation path, the risk to organizations using these applications is considerable.
OpenCVE Enrichment