Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office Outlook that can be triggered by an unauthorized attacker sending specially crafted data over a network. An attacker who succeeds can execute arbitrary code with the privileges of the user running the Outlook client, leading to complete compromise of the affected system. The flaw falls under CWE‑122 and directly threatens confidentiality, integrity, and availability of the host.
Affected Systems
Microsoft products affected include Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, and Microsoft Word 2016. All listed versions are vulnerable; see the Microsoft update guide for exact build ranges.
Risk and Exploitability
The CVSS score of 9.8 marks it high severity, and while the EPSS is not publicly available, the lack of a public fix means attackers may already have custom exploits. The vulnerability is not listed in the CISA KEV catalog; however, given its remote trigger via network traffic, the likely attack vector is externally initiated send to a running Outlook instance. Exploitability is enabled for any user who can send a crafted message or payload to the target system.
OpenCVE Enrichment