Impact
An out‑of‑bounds write in Microsoft Office allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability can compromise confidentiality, integrity, and availability of affected systems if exploited, enabling an attacker to run malicious code with the privileges of the Office process.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024 (including Mac editions). Specific version numbers are not listed, so all current builds of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network, where an attacker can deliver a crafted Office document or data stream that triggers the out‑of‑bounds write. Escalation to system privileges may occur if the Office process runs with elevated rights.
OpenCVE Enrichment