Impact
The flaw is an out‑of‑bounds read in Microsoft Office Outlook that can be triggered by an unauthorized attacker over a network. The read occurs in a code execution path, allowing the attacker to read data beyond the intended buffer and to execute arbitrary code within Outlook. This weakness, identified as CWE‑125, directly endangers the confidentiality, integrity, and availability of any system running the affected Outlook component.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016 are susceptible. Version ranges are not specified in the advisory, but all listed releases contain the vulnerable component.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, signifying a serious exploit impact. EPSS data is not available, so the probability of exploitation cannot be precisely measured, but the fact that an unauthenticated attacker can exploit the flaw over a network raises its risk. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw occurs in the Outlook client accessed via network communications, the likely attack vector is remote, unauthenticated access over the network.
OpenCVE Enrichment