Impact
A heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute arbitrary code locally. The flaw occurs when Office processes a specially crafted document, causing an overflow that leads to code execution with the privileges of the current user. This weakness, a CWE-122 condition, could let an attacker run arbitrary programs, modify or delete data, or establish privileged accounts on the affected system. The vulnerability requires that the user open a malicious Office file, making it exploitable through social engineering or malicious attachments.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version information is not specified in the advisory, so any installation of these products could be vulnerable.
Risk and Exploitability
The CVSS score is 8.4, which is high and indicates a serious threat. The EPSS score remains low (<1%), suggesting that exploitation probability is presently low. The vulnerability is not listed in CISA KEV. An attacker must first persuade a user to open a malicious Office document; once the document is processed, Office will execute code with the current user’s privileges. The impact can be full user‑level control, including installing software, tampering with data, and creating privileged accounts. While the local nature of execution limits abuse to the current user, the seriousness of the effect means patching remains critical.
OpenCVE Enrichment