Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office Word that allows an attacker to read arbitrary data from memory, potentially including credentials or other Confidential information. This buffer overread flaw is identified as CWE‑125 and can lead to loss of confidentiality, with no direct denial of service or code execution capabilities indicated.
Affected Systems
The issue affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Word 2016. No specific version ranges are provided, so any installation of the listed products that has not yet applied the latest security update is potentially vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely network‑based – an attacker can exploit the flaw by sending a crafted document over a network connection or via a shared Office file, without additional deployment prerequisites.
OpenCVE Enrichment