Impact
A heap-based buffer overflow exists in Microsoft Office Word that allows an attacker to execute arbitrary code on a target system. The flaw enables malware payload delivery over a network, potentially compromising confidentiality, integrity, or availability of the affected machine. The weakness is a classic out-of-bounds write (CWE-122).
Affected Systems
Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021 LTSC, Microsoft Office 2024 LTSC, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016 across x86 and x64 architectures, and the corresponding macOS editions.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is not available, so the current exploitation probability is unknown, but the vulnerability is listed as not present in the CISA KEV catalog. The likely attack vector is a network-based delivery of a malicious document, inferred from the description that code can be executed over a network. Attacking systems that rely on Microsoft Office for document handling pose a high risk until the fix is applied.
OpenCVE Enrichment