Impact
A heap‑based buffer overflow exists in Microsoft Word that is triggered by parsing an attacker‑crafted document over a network. This flaw permits execution of arbitrary code with the same privileges as the user who opens the file, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. No specific version numbers are provided beyond these product families.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to exploit this flaw over a network by delivering a malicious Word document through shared folders, email attachments, or other networked channels. Successful exploitation would allow remote code execution with the privileges of the victim user.
OpenCVE Enrichment