Impact
Microsoft Office Word contains a heap‑based buffer overflow that permits an attacker to execute arbitrary code when a malicious document or data is received over the network. The flaw, classified as CWE‑122, can compromise the confidentiality, integrity, and availability of the affected system, potentially allowing a remote attacker to gain full control of the target application or the underlying operating system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016. The CVE information does not specify vulnerable release numbers, so any installation matching these products is potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score is not available, leaving exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog, though it can be triggered over the network by an unauthorized attacker. The likely attack vector involves a network‑sourced malicious file or payload that leverages the buffer overflow to execute code under the Office process context.
OpenCVE Enrichment