Impact
Out-of-bounds read in Microsoft Office Word allows an attacker to read data beyond the intended buffer, potentially exposing sensitive information. The flaw enables an unauthorized attacker to extract data over the network, compromising confidentiality of disclosed content. This vulnerability is a classic breach of data protection, affecting systems that rely on Office for file management and data handling.
Affected Systems
The vulnerability impacts Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016. All current versions of these products are affected as indicated by the CNA. Administrators should verify that any installations of these Office suites are within the affected release set.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available, suggesting limited information about exploitation frequency. The vulnerability is not listed in the CISA KEV catalog, but it can be abused by a remote attacker by sending specially crafted documents or macros over the network, triggering the out-of-bounds read. Attackers would need network access to the vulnerable system and the ability to deliver the exploit payload, but no privilege escalation is required.
OpenCVE Enrichment