Impact
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to read memory data and disclose information over a network. This flaw can compromise confidentiality but does not grant code execution or modify data, creating a moderate‑severity information‑disclosure vulnerability with a CVSS score of 6.5.
Affected Systems
Affected product families include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. Based on the vendor list, these products may be affected, but the exact version ranges are not supplied in the data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of risk. EPSS score is not available, so the exploitation prevalence is unknown. Microsoft has not listed this vulnerability in the CISA KEV catalog. The likely attack vector is network‑based, possibly exploiting a corrupted or malicious Office file that can be opened locally or shared across a network; the attacker can read sensitive data from memory, but cannot gain code execution or privilege escalation.
OpenCVE Enrichment