Impact
A numeric truncation error in Microsoft Office Word permits an attacker to execute arbitrary code with the privileges of the user or, when the document is opened by a trusted account, the system. The flaw permits injection of malicious payloads via network‑delivered Office files. As classified by CWE‑122 and CWE‑197, the vulnerability can lead to full compromise of confidentiality, integrity, and availability on affected machines.
Affected Systems
The weakness affects Microsoft’s Office product line including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Word 2016. No specific version numbers are provided, so all current releases that have not yet applied the patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, but the EPSS score is unavailable, preventing an assessment of current exploit prevalence. The vulnerability is not yet listed in the CISA KEV catalog. Likely the attack vector is the remote delivery of a specially crafted Word document, which when opened triggers the truncation error and achieves code execution.
OpenCVE Enrichment