Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office that permits an unauthenticated attacker to exfiltrate sensitive information across a network. The flaw arises when the application processes data that exceeds expected bounds, exposing memory contents that may contain credentials, personal data, or other confidential material. The impact is the potential for a data breach that could compromise user privacy and regulatory compliance.
Affected Systems
Affected installations include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.
Risk and Exploitability
The CVSS score of 6.5 categorizes the risk as moderate, and there is currently no EPSS score reported or presence in the CISA KEV catalog. Although no known exploits are documented as of the latest advisory, the ability to read arbitrary memory makes the vulnerability attractive for adversaries seeking to gather sensitive data. The attack vector is inferred to be remote, requiring an attacker to deliver malicious input to the Office process over the network. Mitigation requires immediate application of vendor updates, as earlier remediation is not available.
OpenCVE Enrichment